Total
11922 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-2157 | 1 Plogger | 1 Plogger | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE: This is a different vulnerability than CVE-2005-4246. | |||||
CVE-2006-1751 | 1 Michiel Van Baak | 1 Mvblog | 2017-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |||||
CVE-2006-1501 | 1 Oneorzero | 1 Oneorzero | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action. | |||||
CVE-2006-1500 | 1 Tilde | 1 Tilde Cms | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2006-1006 | 1 Sendcard | 1 Sendcard | 2017-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. | |||||
CVE-2006-0772 | 1 Hitachi | 1 Business Logic | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitrary SQL commands via unspecified vectors in the extended receiving box function. | |||||
CVE-2006-0412 | 1 Gencbeyin Web Programlama | 1 Cybershop | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. | |||||
CVE-2006-0269 | 1 Oracle | 1 Oracle10g | 2017-07-20 | 5.5 MEDIUM | N/A |
Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package. | |||||
CVE-2006-0249 | 1 Bitdamaged | 1 Geoblog | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable). | |||||
CVE-2006-0240 | 1 8pixel.net | 1 Simple Blog | 2017-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts. | |||||
CVE-2006-0160 | 1 Venom Board | 1 Venom Board | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3. | |||||
CVE-2006-0159 | 1 Javier Suarez Sanz | 1 Foro Domus | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information. | |||||
CVE-2005-4711 | 1 Neocrome | 1 Land Down Under | 2017-07-20 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in Neocrome Land Down Under (LDU) 801 allows remote attackers to execute arbitrary SQL commands via an HTTP Referer header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2005-4617 | 1 Forperfect | 1 Csupport | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter. | |||||
CVE-2005-4500 | 1 Musicbox | 1 Musicbox | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered. | |||||
CVE-2005-4382 | 1 Citysoft | 1 Community Enterprise | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm. | |||||
CVE-2005-4380 | 1 Bitweaver | 1 Bitweaver | 2017-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php. | |||||
CVE-2005-4198 | 1 Netref | 1 Netref | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Netref 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |||||
CVE-2005-4071 | 1 Cfmagic | 1 Magic Forum Personal | 2017-07-20 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm. | |||||
CVE-2005-4058 | 1 Saralblog | 1 Saralblog | 2017-07-20 | 7.5 HIGH | N/A |
SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php. |