Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17575 1 Groupon Clone Project 1 Groupon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
CVE-2017-17571 1 Foodpanda Clone Project 1 Foodpanda Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17572 1 Amazon Clone Project 1 Amazon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-17570 1 Expedia Clone Project 1 Expedia Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2020-13504 1 Aveva 1 Edna Enterprise Data Historian 2020-09-29 7.5 HIGH 9.8 CRITICAL
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
CVE-2020-13505 1 Aveva 1 Edna Enterprise Data Historian 2020-09-25 7.5 HIGH 9.8 CRITICAL
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
CVE-2020-17506 1 Articatech 1 Web Proxy 2020-09-22 7.5 HIGH 9.8 CRITICAL
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
CVE-2020-23833 1 Projectworlds 1 House Rental 2020-09-18 7.5 HIGH 9.8 CRITICAL
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
CVE-2020-24197 1 Stock Management System Project 1 Stock Management System 2020-09-15 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.
CVE-2020-24193 1 Daily Tracker System Project 1 Daily Tracker System 2020-09-10 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
CVE-2018-13792 1 Abbyy 1 Flexicapture 2020-09-10 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.
CVE-2020-25005 1 Heybbs Project 1 Heybbs 2020-09-04 7.5 HIGH 9.8 CRITICAL
Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.
CVE-2020-25004 1 Heybbs Project 1 Heybbs 2020-09-04 7.5 HIGH 9.8 CRITICAL
Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.
CVE-2020-25006 1 Heybbs Project 1 Heybbs 2020-09-04 7.5 HIGH 9.8 CRITICAL
Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote attacker to execute arbitrary code.
CVE-2019-18344 1 Online Grading System Project 1 Online Grading System 2020-09-03 7.5 HIGH 9.8 CRITICAL
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).
CVE-2020-23973 1 Kandnconcepts Club Cms Project 1 Kandnconcepts Club Cms 2020-09-02 7.5 HIGH 9.8 CRITICAL
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23980 1 Designmasterevents 1 Conference Management 2020-09-01 7.5 HIGH 9.8 CRITICAL
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-6637 1 Os4ed 1 Opensis 2020-09-01 7.5 HIGH 9.8 CRITICAL
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
CVE-2020-5624 1 Riken 1 Xoonips 2020-08-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2020-23976 1 Webexcels 1 Ecommerce Cms 2020-08-31 7.5 HIGH 9.8 CRITICAL
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23978 1 Soluzioneglobale 1 Ecommerce Cms 2020-08-28 7.5 HIGH 9.8 CRITICAL
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
CVE-2020-23979 1 13enforme 1 13enforme Cms 2020-08-28 7.5 HIGH 9.8 CRITICAL
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVE-2016-4837 1 Ec-cube 1 Discount Coupon 2020-08-27 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2018-18251 1 Deltek 1 Vision 2020-08-24 7.5 HIGH 9.8 CRITICAL
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server. Client HTTP calls can be manipulated by one of several means to execute arbitrary SQL statements (similar to SQLi) or possibly have unspecified other impact via this custom protocol. To perform these attacks an authenticated session is first required. In some cases client calls are obfuscated by encryption, which can be bypassed due to hard-coded keys and an insecure key rotation protocol. Impacts may include remote code execution in some deployments; however, the vendor states that this cannot occur when the installation documentation is heeded.
CVE-2019-11196 1 Vpcsbd 1 Integrated University Management System 2020-08-24 10.0 HIGH 9.8 CRITICAL
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).
CVE-2019-8600 1 Apple 6 Icloud, Iphone Os, Itunes and 3 more 2020-08-24 7.5 HIGH 9.8 CRITICAL
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
CVE-2019-16894 1 Inoideas 1 Inoerp 2020-08-24 7.5 HIGH 9.8 CRITICAL
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
CVE-2019-10913 1 Sensiolabs 1 Symfony 2020-08-24 7.5 HIGH 9.8 CRITICAL
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
CVE-2020-24208 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2020-08-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
CVE-2020-12606 1 Dbsoft 1 Sglac 2020-08-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server. Command execution can be easily achieved by using the xp_cmdshell stored procedure.
CVE-2020-8211 1 Citrix 1 Xenmobile Server 2020-08-20 7.5 HIGH 9.8 CRITICAL
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
CVE-2017-15982 1 Geniusocean 1 News 2020-08-19 7.5 HIGH 9.8 CRITICAL
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
CVE-2017-15981 1 Geniusocean 1 Newspaper 2020-08-19 7.5 HIGH 9.8 CRITICAL
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
CVE-2017-15971 1 Softdatepro 1 Same Date Pro 2020-08-19 7.5 HIGH 9.8 CRITICAL
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
CVE-2020-7356 1 Cayintech 1 Xpost 2020-08-12 10.0 HIGH 9.8 CRITICAL
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
CVE-2020-13921 1 Apache 1 Skywalking 2020-08-07 7.5 HIGH 9.8 CRITICAL
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.
CVE-2020-16165 1 Springblade Project 1 Springblade 2020-08-05 7.5 HIGH 9.8 CRITICAL
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
CVE-2015-9098 1 Red-gate 1 Sql Monitor 2020-08-04 10.0 HIGH 9.8 CRITICAL
In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. If the Base Monitor is connecting to these machines using an account with SQL admin privileges, then code execution on the operating system can result in full system compromise (if Microsoft SQL Server is running with local administrator privileges).
CVE-2019-20361 1 Icegram 1 Email Subscribers \& Newsletters 2020-07-27 7.5 HIGH 9.8 CRITICAL
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
CVE-2016-9488 1 Manageengine 1 Applications Manager 2020-07-27 7.5 HIGH 9.8 CRITICAL
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
CVE-2020-14497 1 Advantech 1 Iview 2020-07-21 7.5 HIGH 9.8 CRITICAL
Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely execute code.
CVE-2020-13926 1 Apache 1 Kylin 2020-07-21 7.5 HIGH 9.8 CRITICAL
Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous versions after 2.0 should upgrade to 3.1.0.
CVE-2020-15504 1 Sophos 1 Xg Firewall Firmware 2020-07-14 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.
CVE-2020-15539 1 We-com 1 Municipality Portal Cms 2020-07-13 7.5 HIGH 9.8 CRITICAL
SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
CVE-2020-8520 1 Phpzag 1 Phpzag 2020-07-09 7.5 HIGH 9.8 CRITICAL
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8519 1 Phpzag 1 Phpzag 2020-07-09 7.5 HIGH 9.8 CRITICAL
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8521 1 Phpzag 1 Phpzag 2020-07-09 7.5 HIGH 9.8 CRITICAL
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2019-20896 1 Webchess Project 1 Webchess 2020-07-09 7.5 HIGH 9.8 CRITICAL
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
CVE-2020-15540 1 We-com 1 Opendata Cms 2020-07-09 7.5 HIGH 9.8 CRITICAL
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-14092 1 Ithemes 1 Paypal Pro 2020-07-08 7.5 HIGH 9.8 CRITICAL
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.