Total
11922 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-6001 | 1 Cybozu | 1 Garoon | 2014-01-03 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2013-6929 | 1 Cybozu | 1 Garoon | 2013-12-30 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input. | |||||
CVE-2013-6787 | 1 Chamilo | 1 Chamilo Lms | 2013-12-27 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter. | |||||
CVE-2013-2627 | 1 Idleman | 1 Leed | 2013-12-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action. | |||||
CVE-2013-6839 | 1 Instantsoft | 1 Instantcms | 2013-12-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id]. | |||||
CVE-2013-6985 | 1 Enorth | 1 Webpublisher Cms | 2013-12-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter. | |||||
CVE-2013-6875 | 1 Nagios | 1 Nagios Xi | 2013-11-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php. | |||||
CVE-2013-5694 | 1 Opsview | 1 Opsview | 2013-11-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter. | |||||
CVE-2013-4715 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2013-11-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2013-5517 | 1 Cisco | 1 Unified Communications Domain Manager | 2013-10-17 | 5.5 MEDIUM | N/A |
SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567. | |||||
CVE-2013-5931 | 1 Real-estate-php-script | 1 Real Estate Php Script | 2013-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |||||
CVE-2013-4137 | 1 Status | 1 Statusnet | 2013-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format." | |||||
CVE-2013-4682 | 2 Bas Van Beek, Typo3 | 2 Multishop, Typo3 | 2013-10-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Multishop extension before 2.0.39 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2013-5697 | 2 Apache, Simone Tellini | 2 Http Server, Mod Accounting | 2013-10-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header. | |||||
CVE-2012-3132 | 1 Oracle | 1 Database Server | 2013-10-11 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS. | |||||
CVE-2013-5967 | 1 Alienvault | 1 Open Source Security Information Management | 2013-10-10 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/. | |||||
CVE-2013-4809 | 1 Hp | 2 Identity Driven Manager, Procurve Manager | 2013-09-26 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter. | |||||
CVE-2013-5917 | 2 Rodrigo Coimbra, Wordpress | 2 Nospam Pti, Wordpress | 2013-09-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter. | |||||
CVE-2010-1049 | 1 Uiga | 1 Business Portal | 2013-09-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php. | |||||
CVE-2013-3602 | 1 Trivantis | 1 Coursemill Learning Management System | 2013-09-06 | 7.5 HIGH | N/A |
SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter. |