Total
11922 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-3913 | 1 Gforge | 1 Gforge | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2007-3909 | 1 Bandersnatch | 1 Bandersnatch | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors. | |||||
CVE-2007-3677 | 1 Maxsi | 1 Evisit Analyst | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Maxsi eVisit Analyst allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) idsp1.pl, (2) ip.pl, and (3) einsite_director.pl. NOTE: this issue can be leveraged for path disclosure from resulting error messages. | |||||
CVE-2007-0695 | 1 Free Lan Intra Internet Portal | 1 Free Lan Intra Internet Portal | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions. | |||||
CVE-2007-0350 | 1 Sme | 1 Filemailer | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346. | |||||
CVE-2006-7170 | 1 Koan Software | 1 Mega Mall | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php. | |||||
CVE-2006-7089 | 1 Ban | 1 Ban | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2006-7025 | 1 Sangwan Kim | 1 Bookmark4u | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter. | |||||
CVE-2006-6912 | 1 Phpmyfaq | 1 Phpmyfaq | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename parameter. | |||||
CVE-2006-6367 | 1 Duware | 3 Dudownload, Dunews, Dupaypal | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976. | |||||
CVE-2004-2751 | 1 Postnuke Software Foundation | 1 Postnuke | 2017-07-29 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | |||||
CVE-2004-2737 | 1 Netsupport | 1 Dna Helpdesk | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter. | |||||
CVE-2004-2716 | 1 Php Heaven | 1 Phpmychat | 2017-07-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters. | |||||
CVE-2003-1523 | 1 Dbmail | 1 Dbmail | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors. | |||||
CVE-2003-1504 | 1 Goldscripts | 1 Goldlink | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php. | |||||
CVE-2003-1458 | 1 Ttcms | 2 Ttcms, Ttforum | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name. | |||||
CVE-2003-1435 | 1 Francisco Burzi | 1 Php-nuke | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module. | |||||
CVE-2002-2383 | 1 F2html.pl | 1 F2html.pl | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names. | |||||
CVE-2002-2305 | 1 Phpsecure.org | 1 Immobilier | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter. | |||||
CVE-2002-2304 | 1 Myphpsoft | 1 Myphplinks | 2017-07-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter. |