Total
11922 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-3076 | 1 Blentz | 1 Smbind | 2011-01-19 | 7.5 HIGH | N/A |
The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page. | |||||
CVE-2010-3922 | 1 Sixapart | 1 Movabletype | 2011-01-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-0139 | 1 Cisco | 1 Unified Meetingplace | 2011-01-07 | 9.0 HIGH | N/A |
Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691. | |||||
CVE-2010-4609 | 1 Html-edit | 1 Html-edit Cms | 2011-01-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL commands via the nuser parameter in a registrate action. | |||||
CVE-2010-4632 | 1 Pilotcart | 1 Pilot Cart | 2010-12-31 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL commands via the (1) article parameter to kb.asp, (2) specific parameter to cart.asp, (3) countrycode parameter to contact.asp, and the (4) srch parameter to search.asp. NOTE: the article parameter to pilot.asp is already covered by CVE-2008-2688. | |||||
CVE-2010-4638 | 2 Iptechinside, Joomla | 2 Com Jquarks4s, Joomla\! | 2010-12-31 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the q parameter in a submitSurvey action to index.php. | |||||
CVE-2010-4614 | 1 Mhproducts | 1 Ero Auktion | 2010-12-30 | 7.5 HIGH | N/A |
SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | |||||
CVE-2010-4404 | 2 Anything-digital, Joomla | 2 Sh404sef, Joomla\! | 2010-12-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-1093 | 1 1024cms | 1 1024 Cms | 2010-12-14 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action. | |||||
CVE-2010-4517 | 2 Harmistechnology, Joomla | 2 Com Jeauto, Joomla\! | 2010-12-10 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the char parameter in an item action to index.php. | |||||
CVE-2010-4505 | 1 Injader | 1 Injader | 2010-12-09 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in login.php in Injader 2.4.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) un and (2) pw parameters. | |||||
CVE-2010-4503 | 1 Aigaion | 1 Aigaion | 2010-12-09 | 7.5 HIGH | N/A |
SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in an export action. | |||||
CVE-2010-4500 | 1 Mrcgiguy | 1 Freeticket | 2010-12-09 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) subject, and (4) message parameters in a sendmess action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-4360 | 1 Jurpo | 1 Jurpopage | 2010-12-02 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Jurpopage 0.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) note and (2) pg parameters, different vectors than CVE-2010-4359. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-4365 | 2 Harmistechnology, Joomla | 2 Com Jeajaxeventcalendar, Joomla\! | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php. | |||||
CVE-2010-4357 | 1 Boka | 1 Siteengine | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter. | |||||
CVE-2010-4356 | 1 Site2nite | 1 Big Truck Broker | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in news_default.asp in Site2Nite Big Truck Broker allows remote attackers to execute arbitrary SQL commands via the txtSiteId parameter. | |||||
CVE-2010-4359 | 1 Jurpo | 1 Jurpopage | 2010-12-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Jurpopage 0.2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||||
CVE-2010-4271 | 1 Impresscms | 1 Impresscms | 2010-11-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-0609 | 1 Novaboard | 1 Novaboard | 2010-11-03 | 7.5 HIGH | N/A |
SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |