Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-4359 | 1 Jurpo | 1 Jurpopage | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Jurpopage 0.2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||||
CVE-2010-4360 | 1 Jurpo | 1 Jurpopage | 2010-12-02 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Jurpopage 0.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) note and (2) pg parameters, different vectors than CVE-2010-4359. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-4356 | 1 Site2nite | 1 Big Truck Broker | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in news_default.asp in Site2Nite Big Truck Broker allows remote attackers to execute arbitrary SQL commands via the txtSiteId parameter. | |||||
CVE-2010-4357 | 1 Boka | 1 Siteengine | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter. | |||||
CVE-2010-4365 | 2 Harmistechnology, Joomla | 2 Com Jeajaxeventcalendar, Joomla\! | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php. | |||||
CVE-2010-4271 | 1 Impresscms | 1 Impresscms | 2010-11-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-0609 | 1 Novaboard | 1 Novaboard | 2010-11-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-4143 | 1 Phpcheckz | 1 Phpcheckz | 2010-11-03 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2010-3608 | 1 Wire Plastic Design | 1 Wpquiz | 2010-09-27 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php. | |||||
CVE-2010-3601 | 1 Invisionpower | 1 Ibphotohost | 2010-09-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter. | |||||
CVE-2010-3604 | 2 Alex Kellner, Typo3 | 2 Powermail, Typo3 | 2010-09-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-3485 | 1 Lightneasy | 1 Lightneasy | 2010-09-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the userhandle cookie to LightNEasy.php, a different vector than CVE-2008-6593. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-3484 | 1 Lightneasy | 1 Lightneasy | 2010-09-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to LightNEasy.php, a different vector than CVE-2008-6593. | |||||
CVE-2010-3482 | 1 Bouzouste | 1 Primitive Cms | 2010-09-23 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. NOTE: this can be leveraged with CVE-2010-3483 to conduct attacks without authentication. | |||||
CVE-2010-3422 | 2 Joomla, Solventus | 2 Joomla\!, Com Jgen | 2010-09-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. | |||||
CVE-2010-3428 | 1 Intermesh | 1 Group-office | 2010-09-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action. | |||||
CVE-2010-0438 | 1 Otrs | 1 Otrs | 2010-09-09 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2009-4979 | 1 Keil-software | 1 Photokorn Gallery | 2010-08-25 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) where[], (2) sort, (3) order, and (4) Match parameters. | |||||
CVE-2010-3029 | 1 Phpkick | 1 Phpkick | 2010-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote attackers to execute arbitrary SQL commands via the gameday parameter in an overview action. | |||||
CVE-2010-3027 | 1 Tycoon | 1 Baseball Script | 2010-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Tycoon Baseball Script 1.0.9 allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a game_player action. |