Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-5346 | 1 Genixcms | 1 Genixcms | 2019-03-15 | 6.5 MEDIUM | 7.2 HIGH |
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php. | |||||
CVE-2019-9762 | 1 Phpshe | 1 Phpshe | 2019-03-14 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication. | |||||
CVE-2015-4592 | 1 Eclinicalworks | 1 Population Health | 2019-03-13 | 6.5 MEDIUM | 8.8 HIGH |
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input. | |||||
CVE-2017-6097 | 1 Mail-masta Project | 1 Mail-masta | 2019-03-13 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id. | |||||
CVE-2017-6088 | 1 Eyesofnetwork | 1 Eyesofnetwork | 2019-03-13 | 9.0 HIGH | 7.2 HIGH |
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php. | |||||
CVE-2017-6098 | 1 Mail-masta Project | 1 Mail-masta | 2019-03-13 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id. | |||||
CVE-2017-6095 | 1 Mail-masta Project | 1 Mail-masta | 2019-03-13 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id. | |||||
CVE-2017-6096 | 1 Mail-masta Project | 1 Mail-masta | 2019-03-13 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list. | |||||
CVE-2015-1434 | 1 Mylittleforum | 1 My Little Forum | 2019-03-13 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php. | |||||
CVE-2017-6013 | 1 Intelliants | 1 Subrion Cms | 2019-03-12 | 7.5 HIGH | 9.8 CRITICAL |
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. | |||||
CVE-2015-7568 | 1 Yeager | 1 Yeager Cms | 2019-03-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter. | |||||
CVE-2008-6594 | 1 Network-publishing | 1 Rdf Newsfeed Export | 2019-03-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2019-9693 | 1 Cmsmadesimple | 1 Cms Made Simple | 2019-03-12 | 6.5 MEDIUM | 8.8 HIGH |
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id). | |||||
CVE-2017-10842 | 1 Basercms | 1 Basercms | 2019-03-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-7390 | 1 Testlink | 1 Testlink | 2019-03-11 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php. | |||||
CVE-2015-7569 | 1 Yeager | 1 Yeager Cms | 2019-03-11 | 7.5 HIGH | 8.8 HIGH |
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter. | |||||
CVE-2008-2451 | 1 Inmedias | 1 Statistics | 2019-03-08 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2018-17420 | 1 Zrlog | 1 Zrlog | 2019-03-08 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter. | |||||
CVE-2018-16809 | 1 Dolibarr | 1 Dolibarr | 2019-03-08 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit. | |||||
CVE-2018-17416 | 1 Zzcms | 1 Zzcms | 2019-03-08 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter. |