Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-6512 | 1 Codelogic | 1 Freichat | 2015-08-19 | 5.0 MEDIUM | N/A |
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php. | |||||
CVE-2015-6513 | 1 J2store | 1 J2store | 2015-08-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_ids[] parameter to index.php. | |||||
CVE-2014-2022 | 1 Vbulletin | 1 Vbulletin | 2015-08-13 | 7.1 HIGH | N/A |
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request. | |||||
CVE-2014-0821 | 1 Cybozu | 1 Garoon | 2015-08-13 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 and CVE-2013-6931. | |||||
CVE-2014-2316 | 2 Wordpress, Zemanta | 2 Wordpress, Search Everything | 2015-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2014-8375 | 1 Gb-plugins | 1 Gb Gallery Slideshow | 2015-08-06 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php. | |||||
CVE-2014-8507 | 1 Google | 1 Android | 2015-08-06 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135. | |||||
CVE-2014-0729 | 1 Cisco | 1 Unified Communications Manager | 2015-08-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05302. | |||||
CVE-2014-0728 | 1 Cisco | 1 Unified Communications Manager | 2015-08-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05313. | |||||
CVE-2014-3415 | 1 Sharetronix | 1 Sharetronix | 2015-08-01 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group. | |||||
CVE-2013-5015 | 1 Symantec | 2 Endpoint Protection Manager, Protection Center | 2015-07-30 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-2183 | 1 Zeuscart | 1 Zeuscart | 2015-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via the id parameter in a (1) disporders detail or (2) subadminmgt edit action or (3) cid parameter in an editcurrency action to admin/. | |||||
CVE-2013-6321 | 1 Ibm | 4 Atlas Ediscovery Process Management, Atlas Suite, Disposal And Governance Management For It and 1 more | 2015-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2013-6872 | 1 O-dyn | 1 Collabtive | 2015-07-28 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action. | |||||
CVE-2014-0763 | 1 Advantech | 1 Advantech Webaccess | 2015-07-24 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in DBVisitor.dll in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary SQL commands via SOAP requests to unspecified functions. | |||||
CVE-2013-6176 | 1 Emc | 1 Document Sciences Xpression | 2015-07-22 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote authenticated users to execute arbitrary SQL commands via unspecified input to a (1) xAdmin or (2) xDashboard form. | |||||
CVE-2015-2972 | 1 Sysphonic | 1 Thetis | 2015-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Sysphonic Thetis before 2.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-2849 | 1 Antlabs | 6 Inngate Ig 3.01 E, Inngate Ig 3.10 E, Inngate Ig 3.10 M and 3 more | 2015-07-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter. | |||||
CVE-2015-5148 | 1 Livelycart | 1 Livelycart | 2015-07-01 | 7.5 HIGH | N/A |
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search_query parameter to product/search. | |||||
CVE-2015-4348 | 1 Spider Contacts Project | 1 Spider Contacts | 2015-06-30 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access Spider Contacts category administration" permission to execute arbitrary SQL commands via unspecified vectors. |