Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-5430 | 1 Scottmanktelow | 1 Stride Cms | 2018-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem. | |||||
CVE-2007-5189 | 1 X-script | 1 Guestbook | 2018-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters. | |||||
CVE-2007-5220 | 1 Asp Product Catalog | 1 Asp Product Catalog | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters. | |||||
CVE-2007-5131 | 1 Interspire | 1 Activekb Nx | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected. | |||||
CVE-2007-5141 | 1 Sitex | 1 Sitex Cms | 2018-10-15 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in search.php in SiteX CMS 0.7.3 Beta allows remote attackers to execute arbitrary SQL commands via the search parameter. | |||||
CVE-2007-5150 | 1 Nukescripts | 1 Nukesentinel | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125. | |||||
CVE-2007-5151 | 1 Nukescripts | 1 Nukesentinel | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie. | |||||
CVE-2007-4810 | 1 Netjuke | 1 Netjuke | 2018-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php. | |||||
CVE-2007-4835 | 1 Phpmyquote | 1 Phpmyquote | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action. | |||||
CVE-2007-4837 | 1 Proxy Anket | 1 Proxy Anket | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2007-4863 | 1 Quirm | 1 Saxon | 2018-10-15 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter. | |||||
CVE-2007-4881 | 1 Psi-labs | 1 Social Networking Script Psisns | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter. | |||||
CVE-2007-4918 | 1 Gelatocms | 1 Gelatocms | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php. | |||||
CVE-2007-4777 | 1 Joomla | 1 Joomla | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778. | |||||
CVE-2007-4719 | 1 212cafe | 1 212cafeboard | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in read.php in 212cafeBoard 6.30 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2007-4762 | 1 E-smart Cart | 1 E-smart Cart | 2018-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092. | |||||
CVE-2007-4611 | 1 Dale Mooney | 1 Calendar Events | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2007-4456 | 2 Mambo, Parkview Consultants | 2 Mambo, Simplefaq | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo. | |||||
CVE-2007-4491 | 1 Gurur Haber | 1 Gurur Haber | 2018-10-15 | 7.5 HIGH | N/A |
SQL injection vulnerability in uyeler2.php in Gurur haber 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2007-4540 | 1 Olate | 1 Olatedownload | 2018-10-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header. |