Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4487 | 1 Atarone | 1 Atarone | 2017-08-07 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4525 | 1 Ampjuke | 1 Ampjuke | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action. | |||||
CVE-2008-4531 | 1 Drupal | 1 Brilliant Gallery | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338. | |||||
CVE-2008-4534 | 1 Ec-cube | 1 Ec-cube | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-4186 | 1 Webcms | 1 Webcms Portal Edition | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4633 | 1 Drupal | 2 Drupal, Node Clone | 2017-08-07 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote." | |||||
CVE-2008-4647 | 1 Sweetcms | 1 Sweetcms | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2008-4651 | 1 Jetbox | 1 Jetbox Cms | 2017-08-07 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php. | |||||
CVE-2008-4660 | 1 Typo3 | 2 M1 Intern, Typo3 | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-4701 | 1 Liberiacms | 1 Liberia Cms | 2017-08-07 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector than CVE-2008-4700. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4743 | 1 Quidascript | 1 Faq Management Script | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in QuidaScript FAQ Management Script allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |||||
CVE-2008-4744 | 1 Dxproscripts | 1 Dxshopcart | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |||||
CVE-2008-4746 | 1 Uniwin | 1 Ecart Professional | 2017-08-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp. | |||||
CVE-2008-4766 | 1 O2php | 1 Oxygen Bulletin Board | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4768 | 1 Tlm Cms | 1 Tlm Cms | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4806 | 1 Ibm | 1 Lotus Connections | 2017-08-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-4904 | 1 Typosphere | 1 Typo | 2017-08-07 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter. | |||||
CVE-2008-4148 | 1 Drupal | 1 Mailhandler | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API. | |||||
CVE-2008-4344 | 1 6rbscript | 1 6rbscript | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | |||||
CVE-2008-4348 | 1 Outshine | 1 Phportfolio | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter. |