Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-3430 | 1 Allomani | 1 Mobile | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | |||||
CVE-2009-3417 | 2 Idojoomla, Joomla | 2 Com Idoblog, Joomla\! | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627. | |||||
CVE-2009-3419 | 1 Intesync | 1 Miniweb | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter. | |||||
CVE-2009-3446 | 2 Joomla, Rick Estrada | 2 Joomla, Com Mytube | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php. | |||||
CVE-2009-3967 | 1 Ed Charkow | 1 Supercharged Linking | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-3510 | 1 Dataspheric | 1 Linkspheric | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter. | |||||
CVE-2009-3531 | 1 Universe | 1 Universe Cms | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-3514 | 1 Marcin Manek | 1 D.net Cms | 2017-09-18 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php. | |||||
CVE-2009-3528 | 1 Al4us | 1 Mymsg | 2017-09-18 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action. | |||||
CVE-2009-3529 | 1 Radscripts | 1 Radbids | 2017-09-18 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074. | |||||
CVE-2009-3543 | 1 Phenotype-cms | 1 Phenotype Cms | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name). | |||||
CVE-2009-3590 | 1 Vspanel | 1 Vs Panel | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter. | |||||
CVE-2009-3595 | 1 Vspanel | 1 Vs Panel | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter, a different vector than CVE-2009-3590. | |||||
CVE-2009-3965 | 1 Maniacomputer | 1 New5starrating | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter. | |||||
CVE-2009-3659 | 1 Stanback | 1 Bs Counter | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2009-3661 | 2 Blueconstantmedia, Joomla | 2 Com Djcatalog, Joomla | 2017-09-18 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showItem action and (2) cid parameter in a show action to index.php. | |||||
CVE-2009-3667 | 1 Adsdx | 1 Adsdx | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands via the Username. | |||||
CVE-2009-3669 | 2 Foobla, Joomla | 2 Com Foobla Suggestions, Joomla | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php. | |||||
CVE-2009-3712 | 1 Ebayclonescript | 1 Ebay Clone | 2017-09-18 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php. | |||||
CVE-2009-3713 | 1 Morcego | 1 Morcegocms | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string. |