Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4551 | 1 Intesync | 1 Miniweb | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php. | |||||
CVE-2009-2927 | 1 Digitalspinners | 1 Ds Cms | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter. | |||||
CVE-2009-3973 | 1 Turnkeyarcade | 1 Turnkey Arcade Script | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629. | |||||
CVE-2009-4206 | 1 Cmsnx | 1 Million Dollar Text Links | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-3971 | 2 Joomla, Jtips | 2 Joomla\!, Com Jtips | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php. | |||||
CVE-2009-4208 | 1 Open-school | 1 Open-school | 2017-09-18 | 7.5 HIGH | N/A |
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.php. | |||||
CVE-2009-3970 | 1 Phpdirsubmit | 1 Php Dir Submit | 2017-09-18 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action. | |||||
CVE-2017-1002021 | 1 Surveys Project | 1 Surveys | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query. | |||||
CVE-2017-1002022 | 1 Surveys Project | 1 Surveys | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query. | |||||
CVE-2017-1002019 | 1 Eventr Project | 1 Eventr | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter. | |||||
CVE-2017-1002018 | 1 Eventr Project | 1 Eventr | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter. | |||||
CVE-2017-9834 | 1 Calendarscripts | 1 Watupro | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php. | |||||
CVE-2017-14242 | 1 Dolibarr | 1 Dolibarr | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter. | |||||
CVE-2017-14238 | 1 Dolibarr | 1 Dolibarr | 2017-09-18 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter. | |||||
CVE-2015-9226 | 1 Alegrocart | 1 Alegrocart | 2017-09-18 | 6.5 MEDIUM | 7.2 HIGH |
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php. | |||||
CVE-2015-6009 | 1 Refbase | 1 Refbase | 2017-09-15 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382. | |||||
CVE-2015-7297 | 1 Joomla | 1 Joomla\! | 2017-09-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858. | |||||
CVE-2015-7858 | 1 Joomla | 1 Joomla\! | 2017-09-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297. | |||||
CVE-2015-7857 | 1 Joomla | 1 Joomla\! | 2017-09-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php. | |||||
CVE-2015-5052 | 1 Sefrengo | 1 Sefrengo | 2017-09-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Sefrengo before 1.6.5 beta2. |