Total
11641 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2016-9242 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter. | ||||
CVE-2016-9287 | 1 Exponentcms | 1 Exponent Cms | 2016-11-29 | N/A |
In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection. | ||||
CVE-2016-6419 | 1 Cisco | 1 Firepower Management Center | 2016-11-28 | N/A |
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485. | ||||
CVE-2016-5843 | 1 Otrs | 1 Faq | 2016-11-28 | N/A |
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters. | ||||
CVE-2016-5792 | 1 Moxa | 1 Softcms | 2016-11-28 | N/A |
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields. | ||||
CVE-2016-5653 | 1 Misys | 1 Fusioncapital Opics Plus | 2016-11-28 | N/A |
Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter. | ||||
CVE-2016-4522 | 1 Rockwellautomation | 1 Factorytalk Energrymetrix | 2016-11-28 | N/A |
SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2016-1393 | 1 Cisco | 1 Cloud Network Automation Provisioner | 2016-11-28 | N/A |
SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175. | ||||
CVE-2016-0249 | 1 Ibm | 1 Security Guardium | 2016-11-28 | N/A |
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2015-7695 | 2 Debian, Zend | 2 Debian Linux, Zend Framework | 2016-11-28 | N/A |
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query. | ||||
CVE-2015-5452 | 1 Watchguard | 1 Xcs | 2016-11-28 | N/A |
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3. | ||||
CVE-2015-5049 | 1 Ibm | 1 Openpages Grc Platform | 2016-11-28 | N/A |
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2015-4160 | 1 Sap | 1 Ase Database Platform | 2016-11-28 | N/A |
SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes: 2152278. | ||||
CVE-2015-4159 | 1 Sap | 1 Hana Web-based Development Workbench | 2016-11-28 | N/A |
SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes 2153892. | ||||
CVE-2015-4129 | 1 Intelliants | 1 Subrion Cms | 2016-11-28 | N/A |
SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie. | ||||
CVE-2006-6402 | 1 Mystats | 1 Mystats | 2016-11-18 | N/A |
SQL injection vulnerability in mystats.php in MyStats 1.0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the details parameter. | ||||
CVE-2010-2312 | 1 Hauntmax | 1 Haunted House Directory Listing Cms | 2016-11-16 | N/A |
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action. | ||||
CVE-2005-3543 | 1 Phorum | 1 Phorum | 2016-10-18 | N/A |
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter. | ||||
CVE-2005-3046 | 1 Phpmyfaq | 1 Phpmyfaq | 2016-10-18 | N/A |
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field. | ||||
CVE-2005-2983 | 1 Oracle | 1 Reports | 2016-10-18 | N/A |
SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes. |