Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-17624 | 1 Php Multivendor Ecommerce Project | 1 Php Multivendor Ecommerce | 2018-01-02 | 7.5 HIGH | 9.8 CRITICAL |
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | |||||
CVE-2017-17651 | 1 Paid To Read Script Project | 1 Paid To Read Script | 2018-01-02 | 7.5 HIGH | 9.8 CRITICAL |
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter. | |||||
CVE-2017-14508 | 1 Sugarcrm | 1 Sugarcrm | 2017-12-29 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits. | |||||
CVE-2017-17632 | 1 Responsive Events And Movie Ticket Booking Script Project | 1 Responsive Events And Movie Ticket Booking Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |||||
CVE-2017-17623 | 1 Opensource Classified Ads Script Project | 1 Opensource Classified Ads Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |||||
CVE-2017-17631 | 1 Multireligion Responsive Matrimonial Project | 1 Multireligion Responsive Matrimonial | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | |||||
CVE-2017-17633 | 1 Multiplex Movie Theater Booking Script Project | 1 Multiplex Movie Theater Booking Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | |||||
CVE-2017-17634 | 1 Single Theater Booking Script Project | 1 Single Theater Booking Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |||||
CVE-2017-17636 | 1 Mlm Forced Matrix Project | 1 Mlm Forced Matrix | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | |||||
CVE-2017-17637 | 1 Car Rental Script Project | 1 Car Rental Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | |||||
CVE-2017-17635 | 1 Mlm Forex Market Plan Script Project | 1 Mlm Forex Market Plan Script | 2017-12-29 | 7.5 HIGH | 9.8 CRITICAL |
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | |||||
CVE-2014-1651 | 1 Symantec | 1 Web Gateway | 2017-12-27 | 5.8 MEDIUM | N/A |
SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-1650 | 1 Symantec | 1 Web Gateway | 2017-12-27 | 5.2 MEDIUM | N/A |
SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2017-17622 | 1 Online Exam Test Application Script Project | 1 Online Exam Test Application Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. | |||||
CVE-2017-17614 | 1 Hotel Restaurant Reviews And Feedback Script Project | 1 Hotel Restaurant Reviews And Feedback Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Food Order Script 1.0 has SQL Injection via the /list city parameter. | |||||
CVE-2017-17628 | 1 Responsive Realestate Script Project | 1 Responsive Realestate Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | |||||
CVE-2017-17609 | 1 Chartered Accountant Booking Script Project | 1 Chartered Accountant Booking Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. | |||||
CVE-2017-17627 | 1 Readymade Video Sharing Script Project | 1 Readymade Video Sharing Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | |||||
CVE-2017-17626 | 1 Readymade Php Classified Script Project | 1 Readymade Php Classified Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | |||||
CVE-2017-17621 | 1 Multivendor Penny Auction Clone Script Project | 1 Multivendor Penny Auction Clone Script | 2017-12-26 | 7.5 HIGH | 9.8 CRITICAL |
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. |