Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4436 1 Bblog 1 Wbblog 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter.
CVE-2008-4457 1 Memht 1 Memht Portal 2017-09-28 6.8 MEDIUM N/A
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.
CVE-2008-4460 1 Vastal I-tech 1 Mmorpg Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.
CVE-2008-4461 1 Vastal I-tech 1 Dating Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.
CVE-2008-4462 1 Vastal I-tech 1 Visa Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
CVE-2008-4463 1 Vastal I-tech 1 Jobs Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
CVE-2008-4464 1 Vastal I-tech 1 Mag Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-4465 1 Vastal I-tech 1 Dvd Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-4466 1 Vastal I-tech 1 Cosmetics Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-4467 1 Vastal I-tech 1 Toner Cart 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4468 1 Vastal I-tech 1 Share Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4469 1 Vastal I-tech 1 Freelance Zone 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.
CVE-2008-4492 1 Yourownbux 1 Yourownbux 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.
CVE-2008-4494 1 Torrenttrader 1 Torrenttrader 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4495 1 Select Development Solutions 1 Php Auto Dealer 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
CVE-2008-4496 1 Select Development Solutions 1 Php Realtor 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.
CVE-2008-4497 1 Built2go 1 Real Estate Listings 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
CVE-2008-4498 1 Phpautos 1 Phpautos 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-4202 1 Gonafish 1 Linkscaffepro 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.
CVE-2008-4516 1 Galerie 1 Galerie 2017-09-28 7.5 HIGH N/A
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.