Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6451 | 1 Jportal | 1 Jportal | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509. | |||||
CVE-2008-6452 | 1 Oceandir | 1 Oceandir | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-6454 | 1 6rbscript | 1 6rbscript | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action. | |||||
CVE-2008-6464 | 1 Mevin | 1 Basic-php-events-lister | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-6466 | 2 Akirapowered, E107 | 2 Image Gallery, E107 | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action. | |||||
CVE-2008-6467 | 1 Dieselscripts | 1 Diesel Job Site | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter. | |||||
CVE-2008-6468 | 1 Dieselscripts | 1 Diesel Pay | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action. | |||||
CVE-2008-6471 | 1 Mountaingrafix | 1 Easylink | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show action. | |||||
CVE-2008-6475 | 1 Drake Team | 1 Drake Cms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php. | |||||
CVE-2008-6477 | 1 Mumbojumbo | 1 Op4 | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |||||
CVE-2008-6481 | 3 Joomla, Joomprod, Mambo-foundation | 3 Joomla, Com Versioning, Mambo | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php. | |||||
CVE-2008-6484 | 1 Mole-group | 1 Taxi Calc Dist Script | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field. | |||||
CVE-2008-6485 | 1 Softcomplex | 1 Php Image Gallery | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter. | |||||
CVE-2008-6487 | 1 Digiappz | 1 Digiaffiliate | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields. | |||||
CVE-2008-6488 | 1 Softcomplex | 1 Php Image Gallery | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action. | |||||
CVE-2008-6489 | 2 Huseyin Bora Abaci, Joomla | 2 Com Myalbum, Joomla | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php. | |||||
CVE-2008-6525 | 1 Nicephpscripts | 1 Nice Php Faq Script | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field). | |||||
CVE-2008-6526 | 1 Bosdev | 1 Bos Classifieds | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838. | |||||
CVE-2008-6527 | 1 Go4i | 1 Go41.net Asp Forum | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter. | |||||
CVE-2008-7097 | 1 Qsoft-inc | 1 K-rate | 2017-09-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php. |