Vulnerabilities (CVE)

Filtered by CWE-89
Total 11922 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4844 1 Mhproducts 1 Easy Online Shop 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2010-4843 1 Phpwebscripts 1 Ad Manager Pro 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.
CVE-2010-4824 1 Silverstripe 1 Silverstripe 2017-08-29 6.8 MEDIUM N/A
SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.
CVE-2010-4814 1 Bestsoftinc 1 Advance Hotel Booking System 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2010-4812 1 6kbbs 1 6kbbs 2017-08-29 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in 6kbbs 8.0 build 20100901 allow remote attackers to execute arbitrary SQL commands via the (1) tids[] parameter to ajaxadmin.php and the (2) msgids[] parameter to ajaxmember.php.
CVE-2010-4809 1 Liberologico 1 Dbsite 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in DBSite 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2010-4808 1 Valarsoft 1 Webmatic 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2008-7301 1 Sclek 1 Jsite 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2003-1598 1 Wordpress 1 Wordpress 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
CVE-2017-13669 1 Nexusphp 1 Nexusphp 2017-08-28 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
CVE-2017-12679 1 Nexusphp 1 Nexusphp 2017-08-28 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
CVE-2015-3616 1 Fortinet 7 Fortimanager 2000e, Fortimanager 200d, Fortimanager 3000f and 4 more 2017-08-26 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
CVE-2017-12981 1 Nexusphp 1 Nexusphp 2017-08-25 7.5 HIGH 9.8 CRITICAL
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.
CVE-2017-12774 1 Finecms Project 1 Finecms 2017-08-24 7.5 HIGH 9.8 CRITICAL
finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database
CVE-2017-12949 1 Podlove 1 Podlove Podcast Publisher 2017-08-24 6.5 MEDIUM 8.8 HIGH
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.
CVE-2017-12947 1 Easymodal Project 1 Easy Modal 2017-08-22 6.5 MEDIUM 7.2 HIGH
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
CVE-2017-12946 1 Easymodal Project 1 Easy Modal 2017-08-22 6.5 MEDIUM 7.2 HIGH
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
CVE-2016-6195 1 Vbulletin 1 Vbulletin 2017-08-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.
CVE-2017-1174 1 Ibm 1 Sterling B2b Integrator 2017-08-20 6.5 MEDIUM 8.8 HIGH
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.
CVE-2017-12909 1 Nexusphp Project 1 Nexusphp 2017-08-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.