Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17900 1 Dolibarr 1 Dolibarr 2018-01-09 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
CVE-2017-17897 1 Dolibarr 1 Dolibarr 2018-01-09 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2017-17645 1 Phpautoclassifiedscript 1 Bus Booking Script 2018-01-05 7.5 HIGH 9.8 CRITICAL
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-17731 1 Dedecms 1 Dedecms 2018-01-04 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CVE-2017-17730 1 Dedecms 1 Dedecms 2018-01-04 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
CVE-2017-17713 1 Boxug 1 Trape 2018-01-04 7.5 HIGH 9.8 CRITICAL
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.
CVE-2017-17779 1 Paid To Read Script Project 1 Paid To Read Script 2018-01-03 7.5 HIGH 9.8 CRITICAL
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
CVE-2017-15875 1 Sistemagpweb 1 Gpweb 2018-01-02 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.
CVE-2017-17624 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-01-02 7.5 HIGH 9.8 CRITICAL
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
CVE-2017-17651 1 Paid To Read Script Project 1 Paid To Read Script 2018-01-02 7.5 HIGH 9.8 CRITICAL
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
CVE-2017-17632 1 Responsive Events And Movie Ticket Booking Script Project 1 Responsive Events And Movie Ticket Booking Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
CVE-2017-17623 1 Opensource Classified Ads Script Project 1 Opensource Classified Ads Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
CVE-2017-17631 1 Multireligion Responsive Matrimonial Project 1 Multireligion Responsive Matrimonial 2017-12-29 7.5 HIGH 9.8 CRITICAL
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17634 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
CVE-2017-17633 1 Multiplex Movie Theater Booking Script Project 1 Multiplex Movie Theater Booking Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
CVE-2017-17637 1 Car Rental Script Project 1 Car Rental Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
CVE-2017-17636 1 Mlm Forced Matrix Project 1 Mlm Forced Matrix 2017-12-29 7.5 HIGH 9.8 CRITICAL
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
CVE-2017-17635 1 Mlm Forex Market Plan Script Project 1 Mlm Forex Market Plan Script 2017-12-29 7.5 HIGH 9.8 CRITICAL
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
CVE-2017-17622 1 Online Exam Test Application Script Project 1 Online Exam Test Application Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
CVE-2017-17614 1 Hotel Restaurant Reviews And Feedback Script Project 1 Hotel Restaurant Reviews And Feedback Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Food Order Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17628 1 Responsive Realestate Script Project 1 Responsive Realestate Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
CVE-2017-17627 1 Readymade Video Sharing Script Project 1 Readymade Video Sharing Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
CVE-2017-17609 1 Chartered Accountant Booking Script Project 1 Chartered Accountant Booking Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
CVE-2017-17626 1 Readymade Php Classified Script Project 1 Readymade Php Classified Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
CVE-2017-17621 1 Multivendor Penny Auction Clone Script Project 1 Multivendor Penny Auction Clone Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
CVE-2017-17602 1 Advance B2b Script Project 1 Advance B2b Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
CVE-2017-17608 1 Kindergarten - Elementary School Listing Script Project 1 Kindergarten - Elementary School Listing Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Child Care Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17618 1 Kickstarter Clone Script Project 1 Kickstarter Clone Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
CVE-2017-17620 1 Lawyer Search Script Project 1 Lawyer Search Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
CVE-2017-17619 1 Laundry Booking Script Project 1 Laundry Booking Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17617 1 Foodspotting Clone Script Project 1 Foodspotting Clone Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
CVE-2017-17610 1 E-commerce Mlm Software Project 1 E-commerce Mlm Software 2017-12-26 7.5 HIGH 9.8 CRITICAL
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
CVE-2017-17613 1 Freelance Website Script Project 1 Freelance Website Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
CVE-2017-17642 1 Basic Job Site Script Project 1 Basic Job Site Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
CVE-2017-17640 1 Advanced World Database Project 1 Advanced World Database 2017-12-26 7.5 HIGH 9.8 CRITICAL
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
CVE-2017-17638 1 Groupon Clone Script Project 1 Groupon Clone Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
CVE-2017-17648 1 Entrepreneur Dating Script Project 1 Entrepreneur Dating Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
CVE-2017-17641 1 Resume Clone Script Project 1 Resume Clone Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
CVE-2017-17639 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2017-12-26 7.5 HIGH 9.8 CRITICAL
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
CVE-2017-17603 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
CVE-2017-17630 1 Yoga Class Script Project 1 Yoga Class Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17611 1 Doctor Search Script Project 1 Doctor Search Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17604 1 Entrepreneur Bus Booking Script Project 1 Entrepreneur Bus Booking Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
CVE-2017-17629 1 Secure E-commerce Script Project 1 Secure E-commerce Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
CVE-2017-17111 1 Scubez 1 Posty Readymade Classifieds 2017-12-22 7.5 HIGH 9.8 CRITICAL
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
CVE-2017-17605 1 Consumer Complaints Clone Script Project 1 Consumer Complaints Clone Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
CVE-2017-17616 1 Event Calendar Category Script Project 1 Event Calendar Category Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
CVE-2017-17607 1 Cms Auditor Website Project 1 Cms Auditor Website 2017-12-22 7.5 HIGH 9.8 CRITICAL
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
CVE-2017-17606 1 Co-work Space Search Script Project 1 Co-work Space Search Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17600 1 Basic B2b Script Project 1 Basic B2b Script 2017-12-22 7.5 HIGH 9.8 CRITICAL
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.