Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10738 1 Nagios 1 Nagios Xi 2018-06-15 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
CVE-2018-10735 1 Nagios 1 Nagios Xi 2018-06-15 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
CVE-2018-10736 1 Nagios 1 Nagios Xi 2018-06-15 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
CVE-2018-1280 1 Pivotal Software 1 Greenplum Command Center 2018-06-14 5.0 MEDIUM 7.5 HIGH
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.
CVE-2018-10256 1 Hrsale Project 1 Hrsale 2018-06-13 6.5 MEDIUM 8.8 HIGH
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
CVE-2018-1292 1 Apache 1 Fineract 2018-05-22 5.5 MEDIUM 8.1 HIGH
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.
CVE-2018-1291 1 Apache 1 Fineract 2018-05-22 5.5 MEDIUM 8.1 HIGH
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' query parameter by way of the "order" param in such a way to read/update the data for which he doesn't have authorization.
CVE-2018-1289 1 Apache 1 Fineract 2018-05-22 6.5 MEDIUM 8.8 HIGH
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' and 'sortOrder' query parameter in such a way to read/update the data for which he doesn't have authorization.
CVE-2018-8953 1 Ca 1 Workload Automation Ae 2018-05-17 6.5 MEDIUM 8.8 HIGH
CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.
CVE-2018-0530 1 Cybozu 1 Garoon 2018-05-17 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-9839 1 Dolibarr 1 Dolibarr Erp\/crm 2018-05-16 6.5 MEDIUM 8.8 HIGH
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
CVE-2017-18260 1 Dolibarr 1 Dolibarr Erp\/crm 2018-05-16 6.5 MEDIUM 8.8 HIGH
Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).
CVE-2018-10050 1 Iscripts 1 Eswap 2018-05-09 6.5 MEDIUM 7.2 HIGH
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
CVE-2016-1000118 1 Huge-it 1 Slideshow 2018-05-02 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000119 1 Huge-it 1 Catalog 2018-05-02 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2018-8820 1 Square-9 1 Globalforms 2018-04-23 6.0 MEDIUM 7.5 HIGH
An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for the attack can be met by sending the default admin credentials.
CVE-2017-17950 1 Cells 1 Blog 2018-04-13 6.5 MEDIUM 8.8 HIGH
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
CVE-2018-6843 1 Kentico 1 Kentico Cms 2018-04-12 6.5 MEDIUM 7.2 HIGH
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
CVE-2018-8045 1 Joomla 1 Joomla\! 2018-04-09 6.5 MEDIUM 8.8 HIGH
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
CVE-2018-7734 1 Afian 1 Filerun 2018-03-26 6.5 MEDIUM 7.2 HIGH
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.
CVE-2018-7735 1 Afian 1 Filerun 2018-03-26 6.5 MEDIUM 7.2 HIGH
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.
CVE-2018-7579 1 Yzmcms 1 Yzmcms 2018-03-22 6.5 MEDIUM 7.2 HIGH
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.
CVE-2018-1414 1 Ibm 2 Maximo Asset Management, Maximo Asset Management Essentials 2018-03-09 6.5 MEDIUM 8.8 HIGH
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
CVE-2017-5812 1 Hp 1 Network Automation 2018-03-07 5.0 MEDIUM 7.5 HIGH
A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
CVE-2016-10007 1 Dotcms 1 Dotcms 2018-03-05 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
CVE-2016-10008 1 Dotcms 1 Dotcms 2018-03-05 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
CVE-2018-6792 1 Saifor 1 Cvms Hub 2018-03-01 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in Saifor CVMS HUB 1.3.1 allow an authenticated user to execute arbitrary SQL commands via multiple parameters to the /cvms-hub/privado/seccionesmib/secciones.xhtml resource. The POST parameters are j_idt118, j_idt120, j_idt122, j_idt124, j_idt126, j_idt128, and j_idt130 under formularioGestionarSecciones:tablaSeccionesMib:*:filter. The GET parameter is nombreAgente.
CVE-2018-3605 1 Trendmicro 1 Control Manager 2018-03-01 6.5 MEDIUM 8.8 HIGH
TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3607 1 Trendmicro 1 Control Manager 2018-02-27 6.5 MEDIUM 8.8 HIGH
XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3606 1 Trendmicro 1 Control Manager 2018-02-27 6.5 MEDIUM 8.8 HIGH
XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3603 1 Trendmicro 1 Control Manager 2018-02-27 6.5 MEDIUM 8.8 HIGH
A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3604 1 Trendmicro 1 Control Manager 2018-02-27 6.5 MEDIUM 8.8 HIGH
GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3602 1 Trendmicro 1 Control Manager 2018-02-27 6.5 MEDIUM 8.8 HIGH
An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2017-15329 1 Huawei 2 Uma, Uma Firmware 2018-02-26 6.5 MEDIUM 8.8 HIGH
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.
CVE-2018-5695 1 Wpjobboard 1 Wpjobboard 2018-02-01 6.5 MEDIUM 7.2 HIGH
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php.
CVE-2018-5697 1 Icyphoenix 1 Icyphoenix 2018-02-01 6.5 MEDIUM 7.2 HIGH
Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_jr_admin.php, related to functions_kb.php.
CVE-2018-5374 1 Slidervilla 1 Dbox Slider 2018-01-24 6.5 MEDIUM 8.8 HIGH
The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
CVE-2018-5373 1 Slidervilla 1 Smooth Slider 2018-01-24 6.5 MEDIUM 8.8 HIGH
The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter).
CVE-2018-5372 1 Slidervilla 1 Testimonial Slider 2018-01-24 6.5 MEDIUM 8.8 HIGH
The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
CVE-2017-14960 1 Opentext 1 Document Sciences Xpression 2018-01-17 5.0 MEDIUM 7.5 HIGH
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
CVE-2017-5663 1 Apache 1 Fineract 2018-01-12 6.5 MEDIUM 8.8 HIGH
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.
CVE-2015-3637 1 Phpmybackuppro 1 Phpmybackuppro 2018-01-11 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
CVE-2017-17920 1 Rubyonrails 1 Ruby On Rails 2018-01-10 6.8 MEDIUM 8.1 HIGH
** DISPUTED ** SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
CVE-2017-17919 1 Rubyonrails 1 Ruby On Rails 2018-01-10 6.8 MEDIUM 8.1 HIGH
** DISPUTED ** SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
CVE-2017-17917 1 Rubyonrails 1 Ruby On Rails 2018-01-10 6.8 MEDIUM 8.1 HIGH
** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
CVE-2017-17916 1 Rubyonrails 1 Ruby On Rails 2018-01-10 6.8 MEDIUM 8.1 HIGH
** DISPUTED ** SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
CVE-2017-17983 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 6.5 MEDIUM 8.8 HIGH
PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.
CVE-2017-17941 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 6.5 MEDIUM 7.2 HIGH
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.
CVE-2017-1757 1 Ibm 1 Security Guardium 2018-01-03 6.5 MEDIUM 8.8 HIGH
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.
CVE-2017-17829 1 Doditsolutions 1 Bus Booking Script 2018-01-03 6.5 MEDIUM 7.2 HIGH
Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter.