Total
11641 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2015-8604 | 1 Cacti | 1 Cacti | 2016-12-03 | N/A |
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action. | ||||
CVE-2015-8153 | 1 Symantec | 1 Endpoint Protection Manager | 2016-12-03 | N/A |
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2015-2956 | 1 Igreks | 3 Milkystep Light, Milkystep Professional, Milkystep Professional Oem | 2016-12-03 | N/A |
SQL injection vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2015-2679 | 1 Genixcms | 1 Genixcms | 2016-12-03 | N/A |
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php. | ||||
CVE-2015-2562 | 1 Web-dorado | 1 Ecommerce Wd | 2016-12-03 | N/A |
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php. | ||||
CVE-2015-2292 | 1 Yoast | 1 Wordpress Seo | 2016-12-03 | N/A |
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands. | ||||
CVE-2015-2216 | 1 Photocati Media | 1 Photocrati | 2016-12-03 | N/A |
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter. | ||||
CVE-2016-7453 | 1 Exponentcms | 1 Exponent Cms | 2016-12-02 | N/A |
The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection. | ||||
CVE-2016-3659 | 1 Cacti | 1 Cacti | 2016-12-01 | N/A |
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter. | ||||
CVE-2016-3172 | 1 Cacti | 1 Cacti | 2016-12-01 | N/A |
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action. | ||||
CVE-2016-1437 | 1 Cisco | 1 Prime Collaboration Deployment | 2016-11-30 | N/A |
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549. | ||||
CVE-2015-2090 | 1 Sympies | 1 Wordpress Survey And Poll | 2016-11-30 | N/A |
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php. | ||||
CVE-2015-2070 | 1 Etouch | 1 Samepage | 2016-11-30 | N/A |
SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed. | ||||
CVE-2015-2065 | 1 Apptha | 1 Wordpress Video Gallery | 2016-11-30 | N/A |
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php. | ||||
CVE-2015-2035 | 1 Piwigo | 1 Piwigo | 2016-11-30 | N/A |
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php. | ||||
CVE-2015-1000011 | 1 Dukapress Project | 1 Dukapress | 2016-11-30 | N/A |
Blind SQL Injection in wordpress plugin dukapress v2.5.9 | ||||
CVE-2016-9134 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure. | ||||
CVE-2016-9135 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure. | ||||
CVE-2016-9184 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure. | ||||
CVE-2016-9272 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service. |