Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-6654 | 1 Zpanelcp | 1 Zpanel | 2017-09-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685. | |||||
CVE-2014-10034 | 1 Couponphp | 1 Couponphp | 2017-09-07 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b) stores_paginate.php in admin/ajax/. | |||||
CVE-2016-2555 | 1 Atutor | 1 Atutor | 2017-09-07 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php. | |||||
CVE-2014-100020 | 1 Itechscripts | 1 Itechclassifieds | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685. | |||||
CVE-2014-5200 | 1 Fb Gorilla Project | 1 Fb Gorilla | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2014-5192 | 1 Sphider | 1 Sphider | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter. | |||||
CVE-2014-5189 | 1 Leadoctopus | 1 Lead Octopus | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2014-5249 | 1 Biblio Autocomplete Project | 1 Biblio Autocomplete | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-5262 | 1 Cacti | 1 Cacti | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-5275 | 1 Prochatrooms | 1 Text Chat Rooms | 2017-09-07 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter. | |||||
CVE-2014-5440 | 1 Mpexsolutions | 1 Mx-smartimer | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in Login.aspx in MPEX Business Solutions MX-SmartTimer before 13.19.18 allows remote attackers to execute arbitrary SQL commands via the ct100%24CPHContent%24password parameter. | |||||
CVE-2014-7176 | 1 Enalean | 1 Tuleap | 2017-09-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman. | |||||
CVE-2014-6080 | 1 Ibm | 2 Security Access Manager For Mobile, Security Access Manager For Web | 2017-09-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-6233 | 1 Flat Manager Project | 1 Flat Manager | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-6241 | 1 Wt Directory Project | 1 Wt Directory | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-100019 | 1 Pomm-project | 1 Pomm | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the LTree converter in Pomm before 1.1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-8351 | 1 French National Commission On Informatics And Liberty | 1 Cookieviz | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter. | |||||
CVE-2014-8506 | 1 Etiko | 1 Etiko Cms | 2017-09-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Etiko CMS allow remote attackers to execute arbitrary SQL commands via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php. | |||||
CVE-2014-8499 | 1 Manageengine | 1 Password Manager Pro | 2017-09-07 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc. | |||||
CVE-2014-8586 | 1 Cp Multi View Event Calendar Project | 1 Cp Multi View Event Calendar | 2017-09-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter. |