Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-1622 | 1 Ecshop | 1 Ecshop | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action. | |||||
CVE-2009-1626 | 1 Will Kraft | 1 Ez-blog | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||||
CVE-2009-1650 | 1 Tenfourzero | 1 Shutter | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html. | |||||
CVE-2009-1651 | 1 2daybiz | 1 Business Community Script | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter. | |||||
CVE-2009-1655 | 1 Easy-scripts | 1 Answer And Question Script | 2017-09-28 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password. | |||||
CVE-2009-1658 | 1 Realtywebware | 1 Realty Web-base | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1662 | 1 Recipescript | 1 Recipe Script | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php. | |||||
CVE-2009-1734 | 1 Omnisoftsol | 1 Vidsharepro | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |||||
CVE-2009-1736 | 1 Joomla | 2 Com Gsticketsystem, Joomla\! | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php. | |||||
CVE-2009-1741 | 1 Dutchmonkey | 1 Dm Filemanager | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |||||
CVE-2009-1742 | 1 Pc4arb | 1 Pc4 Uploader | 2017-09-28 | 7.5 HIGH | N/A |
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function. | |||||
CVE-2009-1746 | 1 Diangemilang | 1 Dgnews | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | |||||
CVE-2009-1747 | 1 26thavenue | 1 Bspeak | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action. | |||||
CVE-2009-1751 | 1 Realtywebware | 1 Realty Web-base | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-1764 | 1 Bokecc | 1 Maxcms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action. | |||||
CVE-2009-1787 | 1 Phpdirsubmit | 1 Php Dir Submit | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters. | |||||
CVE-2009-1799 | 1 Sebastian-thiele | 1 St-gallery | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php. | |||||
CVE-2009-1804 | 1 Videoscript | 1 Youtube Video Script | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |||||
CVE-2009-1810 | 1 Collector | 1 Mycolex | 2017-09-28 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) medium.php, (4) person.php, or (5) schlagwort.php in modules/, related to classes/class.perform.php. | |||||
CVE-2009-1812 | 1 Collector | 1 Mygesuad | 2017-09-28 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) budget.php, (4) zahlung.php, or (5) adresse.php in modules/, related to classes/class.perform.php. |