Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14508 1 Sugarcrm 1 Sugarcrm 2017-12-30 6.5 MEDIUM 8.8 HIGH
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.
CVE-2017-1606 1 Ibm 1 Financial Transaction Manager 2017-12-26 6.5 MEDIUM 8.8 HIGH
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.
CVE-2017-17615 1 Facebook Clone Script Project 1 Facebook Clone Script 2017-12-26 6.5 MEDIUM 8.8 HIGH
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
CVE-2017-17567 1 Scubez 1 Posty Readymade Classifieds 2017-12-22 5.0 MEDIUM 7.5 HIGH
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
CVE-2017-17695 1 Techno - Portfolio Management Panel Project 1 Techno - Portfolio Management Panel 2017-12-21 6.5 MEDIUM 8.8 HIGH
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.
CVE-2017-1356 1 Ibm 1 Atlas Ediscovery Process Management 2017-12-19 6.5 MEDIUM 8.8 HIGH
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683.
CVE-2017-17103 1 Fiyo 1 Fiyo Cms 2017-12-15 6.5 MEDIUM 8.8 HIGH
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
CVE-2017-17102 1 Fiyo 1 Fiyo Cms 2017-12-14 5.0 MEDIUM 7.5 HIGH
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
CVE-2017-8198 1 Huawei 1 Fusionsphere 2017-12-08 6.5 MEDIUM 7.2 HIGH
FusionSphere V100R006C00SPC102(NFV) has an SQL injection vulnerability. An authenticated, remote attacker could craft interface messages carrying malicious SQL statements and send them to a target device. Successful exploit could allow the attacker to launch an SQL injection attack and execute SQL commands.
CVE-2017-16955 1 Inlinks Project 1 Inlinks 2017-12-07 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.
CVE-2017-1000129 1 S9y 1 Serendipity 2017-11-29 5.0 MEDIUM 7.5 HIGH
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
CVE-2017-11508 1 Tenable 1 Securitycenter 2017-11-22 6.5 MEDIUM 8.8 HIGH
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.
CVE-2017-15949 1 Angry-frog 1 Xavier 2017-11-14 6.5 MEDIUM 7.2 HIGH
Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2017-11-13 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2017-12710 1 Advantech 1 Webaccess 2017-11-10 5.0 MEDIUM 7.5 HIGH
A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.
CVE-2017-15578 1 Phpsugar 1 Php Melody 2017-11-08 6.0 MEDIUM 8.8 HIGH
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
CVE-2017-2133 1 Panasonic 2 Kx-hjb1000, Kx-hjb1000 Firmware 2017-11-07 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-1000000 1 Ipswitch 1 Whatsup Gold 2017-11-03 6.5 MEDIUM 8.8 HIGH
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
CVE-2017-15378 1 Softwarepublico 1 E-sic 2017-10-31 6.5 MEDIUM 8.8 HIGH
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
CVE-2017-14757 1 Opentext 1 Document Sciences Xpression 2017-10-18 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-14758 1 Opentext 1 Document Sciences Xpression 2017-10-18 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-13068 1 Qnap 1 Qts Helpdesk 2017-10-13 5.0 MEDIUM 7.5 HIGH
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
CVE-2017-1000120 1 Frappe 1 Frappe 2017-10-13 6.5 MEDIUM 8.8 HIGH
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
CVE-2017-1311 1 Ibm 1 Insights Foundation For Energy 2017-10-11 6.5 MEDIUM 8.8 HIGH
IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 125719.
CVE-2017-14743 1 Faleemi 2 Fsc-880, Fsc-880 Firmware 2017-10-10 9.3 HIGH 8.1 HIGH
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
CVE-2015-9234 1 Cfpaypal 1 Cp Contact Form With Paypal 2017-10-06 6.5 MEDIUM 7.2 HIGH
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
CVE-2017-14844 1 Dasinfomedia 1 Wpgym Gym Management System 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14842 1 Dasinfomedia 1 Smsmaster Multipurpose Sms Gateway 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
CVE-2017-14846 1 Dasinfomedia 1 Hospital Management System 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14845 1 Dasinfomedia 1 Wpchurch Church Management System 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14847 1 Dasinfomedia 1 Wpams Apartment Management System 2017-10-05 6.5 MEDIUM 8.8 HIGH
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-1002025 1 Add-edit-delete-listing-for-member-module Project 1 Add-edit-delete-listing-for-member-module 2017-09-21 6.5 MEDIUM 7.2 HIGH
Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
CVE-2015-9226 1 Alegrocart 1 Alegrocart 2017-09-18 6.5 MEDIUM 7.2 HIGH
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.
CVE-2015-4724 1 Concrete5 1 Concrete5 2017-09-13 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Concrete5 5.7.3.1.
CVE-2015-3314 1 Tune Library Project 1 Tune Library 2017-09-11 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
CVE-2016-1914 1 Blackberry 1 Blackberry Enterprise Service 2017-09-10 6.8 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
CVE-2015-8334 1 Huawei 2 Vcn500, Vcn500 Firmware 2017-09-07 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.
CVE-2016-10509 1 Opencart 1 Opencart 2017-09-06 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
CVE-2017-10839 1 Seopanel 1 Seo Panel 2017-09-01 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-1446 1 Cisco 1 Webex Meetings Server 2017-09-01 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
CVE-2017-11475 1 Glpi-project 1 Glpi 2017-08-29 6.5 MEDIUM 8.8 HIGH
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
CVE-2017-12949 1 Podlove 1 Podlove Podcast Publisher 2017-08-24 6.5 MEDIUM 8.8 HIGH
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.
CVE-2017-12947 1 Easymodal Project 1 Easy Modal 2017-08-22 6.5 MEDIUM 7.2 HIGH
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
CVE-2017-12946 1 Easymodal Project 1 Easy Modal 2017-08-22 6.5 MEDIUM 7.2 HIGH
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
CVE-2017-1174 1 Ibm 1 Sterling B2b Integrator 2017-08-20 6.5 MEDIUM 8.8 HIGH
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.
CVE-2017-7221 1 Opentext 1 Documentum Content Server 2017-08-16 6.5 MEDIUM 8.8 HIGH
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.
CVE-2017-12585 1 Slims 1 Akasia 2017-08-14 6.5 MEDIUM 8.8 HIGH
SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.
CVE-2017-9603 1 Intensewp 1 Wp Jobs 2017-08-13 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
CVE-2017-9429 1 Event List Project 1 Event List 2017-08-13 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.