Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-2918 | 1 Application Dynamics | 1 Cartweaver | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3. | |||||
CVE-2008-2919 | 1 Gryphonllc | 1 Gryphon Gllcts2 | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter. | |||||
CVE-2008-2921 | 1 Eztechhelp Company | 1 Ezcms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2008-2963 | 1 Myblog | 1 Myblog | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php. | |||||
CVE-2008-2964 | 1 Researchguide | 1 Researchguide | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-2971 | 1 Cistyle | 1 Ciblog | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in links-extern.php in CiBlog 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-2983 | 1 Cwh Underground | 1 Demo4 Cms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-2989 | 1 Homap | 1 Homap | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter. | |||||
CVE-2008-2996 | 1 Gravityboardx | 1 Gravity Board X | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2) board_id parameter in a viewboard action. | |||||
CVE-2008-3025 | 1 Plx Web Studio | 1 Plx Ad Trader | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action. | |||||
CVE-2008-3026 | 1 Oneclick Cms | 1 Oneclick Cms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-3030 | 1 Efes Tech Shop | 1 Efes Tech Shop | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an urunler action. | |||||
CVE-2008-3027 | 1 Vangogh Web Cms | 1 Vangogh Web Cms | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the article_ID parameter to index.php. | |||||
CVE-2008-3035 | 1 Xchangeboard | 1 Xchangeboard | 2017-09-28 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter. | |||||
CVE-2008-0371 | 1 Alilg | 1 Alitalk | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to execute arbitrary SQL commands via (2) the id parameter to (b) inc/usercp.php, related to functionz/usercp.php; or (3) the username parameter to (c) admin/index.php, related to functionz/first_process.php, or (d) index.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-0388 | 1 Wordpress | 1 Wp Forum | 2017-09-28 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI. | |||||
CVE-2008-0397 | 1 Aflog.org | 1 Aflog | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php. | |||||
CVE-2008-0421 | 1 Invision Power Services | 1 Invision Gallery | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command. | |||||
CVE-2008-0424 | 1 Mooseguy Blog System | 1 Mgbs | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter. | |||||
CVE-2008-0429 | 1 Alstrasoft | 1 Forum Pay Per Post Exchange | 2017-09-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action. |