Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4623 | 2 Joomla, Martin Diphoorn | 2 Joomla, Com Ds-syndicate | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.php. | |||||
CVE-2008-4643 | 1 Mywebland | 1 Mystats | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | |||||
CVE-2008-4625 | 2 Shiftthis, Wordpress | 2 Shifthis Newsletter, Wordpress | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683. | |||||
CVE-2008-4627 | 2 Rgallery, Woltlab | 2 Rgallery Plugin, Woltlab Burning Board | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php. | |||||
CVE-2008-4628 | 1 Mywebland | 1 Minibloggie | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter. | |||||
CVE-2008-4642 | 1 Astrospaces | 1 Astrospaces | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action. | |||||
CVE-2008-4650 | 1 Mywebland | 1 Myevent | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter. | |||||
CVE-2008-4653 | 1 Xoops | 2 Makale, Xoops | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-4665 | 1 Datingpro | 1 Matchmaking | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) news_read.php and (2) gifts_show.php. | |||||
CVE-2008-4666 | 1 Deeserver | 1 Ultimate Webboard | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter. | |||||
CVE-2008-4674 | 1 Conkurent | 1 Real Estate | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode. | |||||
CVE-2008-4675 | 1 Phpcounter | 1 Phpcounter | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter. | |||||
CVE-2008-4700 | 1 Liberiacms | 1 Liberia Cms | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_pass cookie parameter. | |||||
CVE-2008-4705 | 1 Phponlinedatingsoftware | 1 Myphpdating | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-4703 | 1 Bosdev | 1 Bosnews | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter. | |||||
CVE-2008-4706 | 1 Vbulletin | 1 Vbgooglemap | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php. | |||||
CVE-2008-4709 | 1 Pilot Group | 1 Etraining | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-4711 | 1 Joovili | 1 Joovili | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php. | |||||
CVE-2008-4713 | 1 212cafe | 1 212cafeboard | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter. | |||||
CVE-2008-4716 | 1 Scriptdemo | 1 Php-lance | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter. |