Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4651 | 1 Jetbox | 1 Jetbox Cms | 2017-08-08 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php. | |||||
CVE-2008-4534 | 1 Ec-cube | 1 Ec-cube | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-4172 | 1 Rfaah | 1 Cars-vehicles Script | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter. | |||||
CVE-2008-3724 | 1 Papoo | 1 Papoo | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl parameter. | |||||
CVE-2008-3701 | 1 Kayako | 1 Supportsuite | 2017-08-08 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action. | |||||
CVE-2008-3090 | 1 Blognplus | 1 Blognplus | 2017-08-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819. | |||||
CVE-2008-2760 | 1 Xigla | 1 Absolute Banner Manager | 2017-08-08 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter. | |||||
CVE-2008-2498 | 1 Mambo-foundation | 1 Mambo | 2017-08-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) articleid and (2) mcname parameters. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-3054 | 1 Typo3 | 1 Branchenbuch Extension | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-2850 | 1 Drupal | 1 Trailscout Module | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API. | |||||
CVE-2008-3051 | 1 Typo3 | 1 Pinboard Extension | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-3056 | 1 Typo3 | 1 Codeon Petition Extension | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-3341 | 1 Jobbex | 1 Jobsite | 2017-08-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in search_result.cfm in Jobbex JobSite allow remote attackers to execute arbitrary SQL commands via the (1) jobcountryid and (2) jobstateid parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-3039 | 1 Typo3 | 1 Dam Frontend Extension | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-2775 | 1 Dt Centrepiece | 1 Dt Centrepiece | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in search.asp in DT Centrepiece 4.0 allows remote attackers to execute arbitrary SQL commands via the searchFor parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-2763 | 1 Xigla | 1 Absolute Live Support Xe | 2017-08-08 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter. | |||||
CVE-2008-2762 | 1 Xigla | 1 Absolute Form Processor Xe | 2017-08-08 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in search.asp in Xigla Absolute Form Processor XE 4.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter. | |||||
CVE-2008-3345 | 1 Myiosoft | 1 Easye-cards | 2017-08-08 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a pickup action. | |||||
CVE-2008-3212 | 1 Scripteen | 1 Free Image Hosting Script | 2017-08-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-2685 | 1 Battleblog | 1 Battleblog | 2017-08-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in article.asp in Battle Blog 1.25 Build 4 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter, a different vector than CVE-2008-2626. |