Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-1813 | 1 Submitterscript | 1 Submitterscript | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the uNev parameter (aka the username field) or (2) the uJelszo parameter (aka the Password field). | |||||
CVE-2009-1814 | 1 Jevontech | 1 Phpenpals | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074. | |||||
CVE-2009-1816 | 1 Mygamescript | 1 My Game Script | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-1818 | 1 Maxcms | 1 Maxcms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action. | |||||
CVE-2009-1819 | 1 2daybiz | 1 Custom T-shirt Design Script | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-1852 | 1 Graphiks | 1 Myforum | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |||||
CVE-2009-1848 | 2 Joomla, Joomlame | 2 Joomla, Com Agoragroup | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php. | |||||
CVE-2009-1850 | 1 Benjamin Curtis | 1 Phpbugtracker | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |||||
CVE-2009-1853 | 1 Kenseiboard | 1 Kensei Board | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action. | |||||
CVE-2009-1913 | 1 Luxbum | 1 Luxbum | 2017-09-28 | 5.1 MEDIUM | N/A |
SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | |||||
CVE-2009-1945 | 1 Tzo | 1 Webcal | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |||||
CVE-2009-1947 | 1 Newsboard | 1 Unclassified Newsboard | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686. | |||||
CVE-2009-1950 | 1 Ahmet Donmez | 1 Webeyes Guest Book | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter. | |||||
CVE-2009-1952 | 1 Propertymaxpro | 1 Propertymax Pro Free | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |||||
CVE-2009-2013 | 1 Frontisgroup | 1 Frontis | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action. | |||||
CVE-2009-2014 | 1 Joomla | 2 Com School, Joomla | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php. | |||||
CVE-2009-2016 | 1 Virtuenetz | 1 Virtue Shopping Mall | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||||
CVE-2009-2017 | 1 Virtuenetz | 1 Virtue Book Store | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||||
CVE-2009-2018 | 1 Jaredeckersley | 1 Mycars | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter. | |||||
CVE-2009-2019 | 1 Virtuenetz | 1 Virtue News Manager | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter. |