Total
11641 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2005-4228 | 1 Phpwebgallery | 1 Phpwebgallery | 2011-03-07 | N/A |
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later reported that the comments.php/sort_by vector also affects 1.7.2 and earlier. | ||||
CVE-2005-4263 | 1 Envolution | 1 Envolution | 2011-03-07 | N/A |
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter. | ||||
CVE-2010-3076 | 1 Blentz | 1 Smbind | 2011-01-19 | N/A |
The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page. | ||||
CVE-2010-3922 | 1 Sixapart | 1 Movabletype | 2011-01-12 | N/A |
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2010-0438 | 1 Otrs | 1 Otrs | 2010-09-09 | N/A |
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | ||||
CVE-2010-1045 | 2 Design-cars, Joomla | 2 Com Productbook, Joomla\! | 2010-06-17 | N/A |
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information. | ||||
CVE-2010-0677 | 1 Katalog.hurricane | 1 Katalog Stron Hurricane | 2010-06-17 | N/A |
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter. | ||||
CVE-2010-1050 | 1 Alexandre Dubus | 1 Audistat | 2010-06-17 | N/A |
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter. | ||||
CVE-2010-0673 | 2 Copperleaf, Wordpress | 2 Photolog, Wordpress | 2010-06-17 | N/A |
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter. | ||||
CVE-2010-1046 | 1 Ryan Marshall | 1 Rostermain | 2010-06-17 | N/A |
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters. | ||||
CVE-2010-0605 | 1 Osticket | 1 Osticket | 2010-06-17 | N/A |
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter. | ||||
CVE-2010-1069 | 1 Proarcadescript | 1 Proarcadescript | 2010-06-17 | N/A |
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2010-0608 | 1 Novaboard | 1 Novaboard | 2010-06-17 | N/A |
SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action. | ||||
CVE-2010-0968 | 1 Geekhelps | 1 Admp | 2010-06-17 | N/A |
SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter. | ||||
CVE-2010-0691 | 1 Jtl-software | 1 Jtl-shop | 2010-06-17 | N/A |
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter. | ||||
CVE-2010-0631 | 1 Eicrasoft | 1 Eicra Car Rental-script | 2010-06-17 | N/A |
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters. | ||||
CVE-2010-0802 | 2 Aleinbeen, Invision Power Services | 2 \(nv2\) Awards, Invision Power Board | 2010-06-17 | N/A |
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action. | ||||
CVE-2010-0763 | 1 Commodityrentals | 1 Vacation Rental Software | 2010-06-17 | N/A |
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action. | ||||
CVE-2010-1366 | 1 Uiga | 1 Fan Club | 2010-06-17 | N/A |
Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters. | ||||
CVE-2010-1654 | 1 Instantrankingseo | 1 Infocus Real Estate | 2010-06-17 | N/A |
Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information. |