Total
11922 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-2614 | 1 Datachecknh | 1 Linkpal | 2009-07-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions LinkPal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-2612 | 1 Prosmdr | 1 Prosmdr | 2009-07-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.aspx in ProSMDR allows remote attackers to execute arbitrary SQL commands via the txtUser parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-2388 | 1 Shalwan | 1 Opial | 2009-07-16 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-2436 | 1 Phponlinedatingsoftware | 1 Myphpdating | 2009-07-13 | 7.5 HIGH | N/A |
SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter. | |||||
CVE-2009-2428 | 1 Tauschregal.de | 1 Tausch Ticket Script | 2009-07-13 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors. | |||||
CVE-2009-2423 | 1 Ebayclonescript | 1 Ebay Clone | 2009-07-13 | 7.5 HIGH | N/A |
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action. | |||||
CVE-2009-2427 | 1 Jobbr | 1 Jobbr | 2009-07-13 | 7.5 HIGH | N/A |
SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter. | |||||
CVE-2009-2345 | 1 Clansphere | 1 Clansphere | 2009-07-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components. | |||||
CVE-2007-6727 | 1 Max Kervin | 1 Kervinet Forum | 2009-07-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in topic.php in KerviNet Forum 1.1 allows remote attackers to execute arbitrary SQL commands via the forum parameter. | |||||
CVE-2009-2106 | 2 Projektseminar Proservice Wwu, Typo3 | 2 Virtual Civil Services, Typo3 | 2009-07-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2009-2103 | 2 Steve Grundell, Typo3 | 2 Frontend Mp3 Player, Typo3 | 2009-06-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2009-2105 | 1 Kasper Skrhj | 1 References Database | 2009-06-23 | 7.5 HIGH | N/A |
SQL injection vulnerability in the References database (t3references) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2009-2128 | 1 Elvinbts | 1 Elvinbts | 2009-06-22 | 7.5 HIGH | N/A |
SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field. | |||||
CVE-2009-2082 | 1 Creative Web Solutions | 1 Multi-level Cms | 2009-06-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-0543 | 1 Proftpd | 1 Proftpd | 2009-06-09 | 6.8 MEDIUM | N/A |
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres. | |||||
CVE-2009-1909 | 1 Openskip | 1 Skip | 2009-06-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2009-1851 | 1 Benjamin Curtis | 1 Phpbugtracker | 2009-06-02 | 7.5 HIGH | N/A |
SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-1585 | 1 R020 | 1 Tematres | 2009-05-13 | 4.4 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id_correo_electronico and (2) id_password parameters to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-6802 | 1 Phpexplorer | 1 Phphotogallery | 2009-05-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-1433 | 1 Silverstripe | 1 Silverstripe | 2009-04-27 | 7.5 HIGH | N/A |
SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter. |