Total
11641 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2013-2046 | 1 Owncloud | 1 Owncloud | 2014-03-10 | N/A |
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2013-2045 | 1 Owncloud | 1 Owncloud | 2014-03-10 | N/A |
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2014-2211 | 1 Posh Project | 1 Posh | 2014-03-07 | N/A |
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter. | ||||
CVE-2014-2245 | 1 Cmsmadesimple | 1 Cms Made Simple | 2014-03-07 | N/A |
SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information. | ||||
CVE-2013-6930 | 1 Cybozu | 1 Garoon | 2014-02-21 | N/A |
SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929. | ||||
CVE-2013-6931 | 1 Cybozu | 1 Garoon | 2014-02-21 | N/A |
SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929. | ||||
CVE-2013-4662 | 1 Civicrm | 1 Civicrm | 2014-02-21 | N/A |
The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick. | ||||
CVE-2013-5012 | 1 Symantec | 1 Web Gateway | 2014-02-11 | N/A |
Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2013-1852 | 1 Kolja Schleich | 1 Leaguemanager | 2014-02-05 | N/A |
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php. | ||||
CVE-2013-1617 | 1 Symantec | 3 Web Gateway, Web Gateway Appliance 8450, Web Gateway Appliance 8490 | 2014-01-17 | N/A |
Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2013-7139 | 1 Cynthia Fridsma | 1 Horizon Quick Content Management System | 2014-01-10 | N/A |
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter. | ||||
CVE-2013-7225 | 1 Fatfreecrm | 1 Fat Free Crm | 2014-01-03 | N/A |
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature. | ||||
CVE-2013-6001 | 1 Cybozu | 1 Garoon | 2014-01-03 | N/A |
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2013-6929 | 1 Cybozu | 1 Garoon | 2013-12-30 | N/A |
SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input. | ||||
CVE-2013-6787 | 1 Chamilo | 1 Chamilo Lms | 2013-12-27 | N/A |
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter. | ||||
CVE-2013-2627 | 1 Idleman | 1 Leed | 2013-12-23 | N/A |
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action. | ||||
CVE-2013-6839 | 1 Instantsoft | 1 Instantcms | 2013-12-16 | N/A |
SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id]. | ||||
CVE-2013-6985 | 1 Enorth | 1 Webpublisher Cms | 2013-12-11 | N/A |
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter. | ||||
CVE-2013-5517 | 1 Cisco | 1 Unified Communications Domain Manager | 2013-10-17 | N/A |
SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567. | ||||
CVE-2012-3132 | 1 Oracle | 1 Database Server | 2013-10-11 | N/A |
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS. |