Search
Total
1733 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-5488 | 1 Earclink | 1 Espcms-p8 | 2019-02-14 | 5.0 MEDIUM | 7.5 HIGH |
| EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database. | |||||
| CVE-2015-7999 | 1 Citrix | 1 Command Center | 2019-02-13 | 6.5 MEDIUM | 8.1 HIGH |
| Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
| CVE-2018-7065 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2019-02-05 | 6.5 MEDIUM | 7.2 HIGH |
| An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix. | |||||
| CVE-2018-1000890 | 1 Frontaccounting | 1 Frontaccounting | 2019-01-30 | 5.0 MEDIUM | 7.5 HIGH |
| FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application. | |||||
| CVE-2019-6691 | 1 Phpwind | 1 Phpwind | 2019-01-25 | 6.5 MEDIUM | 7.2 HIGH |
| phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option. | |||||
| CVE-2019-6127 | 1 Xiaocms | 1 Xiaocms | 2019-01-23 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename. | |||||
| CVE-2018-20730 | 1 Nedi | 1 Nedi | 2019-01-22 | 5.0 MEDIUM | 7.5 HIGH |
| A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component. | |||||
| CVE-2018-20719 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2019-01-18 | 6.5 MEDIUM | 8.8 HIGH |
| In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter. | |||||
| CVE-2018-20713 | 1 Shopware | 1 Shopware | 2019-01-18 | 6.5 MEDIUM | 8.8 HIGH |
| Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. | |||||
| CVE-2019-3494 | 1 Simply-blog Project | 1 Simply-blog | 2019-01-16 | 6.4 MEDIUM | 7.5 HIGH |
| Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter. | |||||
| CVE-2018-16175 | 1 Thimpress | 1 Learnpress | 2019-01-11 | 6.5 MEDIUM | 7.2 HIGH |
| SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |||||
| CVE-2018-19998 | 1 Dolibarr | 1 Dolibarr | 2019-01-11 | 6.5 MEDIUM | 8.8 HIGH |
| SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter. | |||||
| CVE-2018-1000630 | 1 Battelle | 1 V2i Hub | 2019-01-11 | 6.5 MEDIUM | 7.2 HIGH |
| Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/pluginStatus.php using the jtSorting or id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. | |||||
| CVE-2018-19994 | 1 Dolibarr | 1 Dolibarr | 2019-01-09 | 6.5 MEDIUM | 8.8 HIGH |
| An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter. | |||||
| CVE-2018-1000867 | 1 Webidsupport | 1 Webid | 2019-01-07 | 6.5 MEDIUM | 8.8 HIGH |
| WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f. | |||||
| CVE-2018-20329 | 1 Chamilo | 1 Chamilo Lms | 2019-01-07 | 5.5 MEDIUM | 8.1 HIGH |
| Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information. | |||||
| CVE-2018-20061 | 1 Frappe | 1 Erpnext | 2019-01-02 | 5.0 MEDIUM | 7.5 HIGH |
| A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen arguments, a SQL attack can be carried out which allows SQL queries to be constructed to return any columns from any tables in the database. This is related to /api/resource/Item?fields= URIs, frappe.get_list, and frappe.call. | |||||
| CVE-2018-20018 | 1 S-cms | 1 S-cms | 2018-12-30 | 5.0 MEDIUM | 7.5 HIGH |
| S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI. | |||||
| CVE-2018-1002000 | 1 Kibokolabs | 1 Arigato Autoresponder And Newsletter | 2018-12-27 | 6.5 MEDIUM | 7.2 HIGH |
| There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request. | |||||
| CVE-2018-19898 | 1 Thinkcmf | 1 Thinkcmf | 2018-12-26 | 6.5 MEDIUM | 8.8 HIGH |
| ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action. | |||||
| CVE-2018-19897 | 1 Thinkcmf | 1 Thinkcmf | 2018-12-26 | 6.5 MEDIUM | 7.2 HIGH |
| ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action. | |||||
| CVE-2018-19896 | 1 Thinkcmf | 1 Thinkcmf | 2018-12-26 | 6.5 MEDIUM | 7.2 HIGH |
| ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action. | |||||
| CVE-2018-19895 | 1 Thinkcmf | 1 Thinkcmf | 2018-12-26 | 6.5 MEDIUM | 7.2 HIGH |
| ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the parentid parameter in a nav action. | |||||
| CVE-2018-19894 | 1 Thinkcmf | 1 Thinkcmf | 2018-12-26 | 6.5 MEDIUM | 7.2 HIGH |
| ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action. | |||||
| CVE-2018-19549 | 1 Interspire | 1 Email Marketer | 2018-12-18 | 6.5 MEDIUM | 8.8 HIGH |
| Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. | |||||
| CVE-2018-19553 | 1 Interspire | 1 Email Marketer | 2018-12-18 | 6.5 MEDIUM | 8.8 HIGH |
| Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php | |||||
| CVE-2018-19552 | 1 Interspire | 1 Email Marketer | 2018-12-18 | 6.5 MEDIUM | 8.8 HIGH |
| Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. | |||||
| CVE-2018-19551 | 1 Interspire | 1 Email Marketer | 2018-12-18 | 6.5 MEDIUM | 8.8 HIGH |
| Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php. | |||||
| CVE-2018-19434 | 1 Weberp | 1 Weberp | 2018-12-18 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter. | |||||
| CVE-2018-19435 | 1 Weberp | 1 Weberp | 2018-12-18 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter. | |||||
| CVE-2018-19436 | 1 Weberp | 1 Weberp | 2018-12-18 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter. | |||||
| CVE-2018-19331 | 1 S-cms | 1 S-cms | 2018-12-18 | 5.0 MEDIUM | 7.5 HIGH |
| An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter. | |||||
| CVE-2018-19349 | 1 Seacms | 1 Seacms | 2018-12-17 | 6.5 MEDIUM | 7.2 HIGH |
| In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php. | |||||
| CVE-2018-0685 | 1 Neo | 1 Debun Pop | 2018-12-17 | 6.5 MEDIUM | 8.8 HIGH |
| SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search. | |||||
| CVE-2018-18550 | 1 Serverscheck | 1 Serverscheck | 2018-12-04 | 6.5 MEDIUM | 8.8 HIGH |
| ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user. | |||||
| CVE-2018-18788 | 1 Zzcms | 1 Zzcms | 2018-12-04 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.) | |||||
| CVE-2018-18784 | 1 Zzcms | 1 Zzcms | 2018-12-04 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.) | |||||
| CVE-2018-18790 | 1 Zzcms | 1 Zzcms | 2018-12-04 | 6.5 MEDIUM | 7.2 HIGH |
| An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.) | |||||
| CVE-2018-18211 | 1 Pbootcms | 1 Pbootcms | 2018-11-26 | 6.8 MEDIUM | 8.1 HIGH |
| PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | |||||
| CVE-2018-17562 | 1 Multitech | 1 Faxfinder | 2018-11-21 | 5.0 MEDIUM | 7.5 HIGH |
| Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points. | |||||
| CVE-2018-7107 | 1 Hpe | 1 Device Entitlement Gateway | 2018-11-21 | 6.5 MEDIUM | 8.8 HIGH |
| A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege. | |||||
| CVE-2018-17283 | 1 Zohocorp | 1 Manageengine Opmanager | 2018-11-09 | 5.0 MEDIUM | 7.5 HIGH |
| Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter. | |||||
| CVE-2016-9048 | 1 Processmaker | 1 Processmaker | 2018-11-09 | 6.5 MEDIUM | 7.4 HIGH |
| Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system. | |||||
| CVE-2018-16436 | 1 Gxlcms | 1 Gxlcms | 2018-11-05 | 6.5 MEDIUM | 7.2 HIGH |
| Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. | |||||
| CVE-2014-6045 | 1 Phpmyfaq | 1 Phpmyfaq | 2018-10-31 | 6.5 MEDIUM | 7.2 HIGH |
| SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function. | |||||
| CVE-2018-3884 | 1 Erpnext | 1 Erpnext | 2018-10-30 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | |||||
| CVE-2018-3882 | 1 Erpnext | 1 Erpnext | 2018-10-29 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | |||||
| CVE-2018-3883 | 1 Erpnext | 1 Erpnext | 2018-10-29 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | |||||
| CVE-2018-3885 | 1 Erpnext | 1 Erpnext | 2018-10-29 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | |||||
| CVE-2018-3879 | 1 Samsung | 2 Sth-eth-250, Sth-eth-250 Firmware | 2018-10-26 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON injection which in turn leads to a SQL injection in the video-core database. An attacker can send a series of HTTP requests to trigger this vulnerability. | |||||
