Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3256 1 Siteframe 2 Siteframe Beaumont, Siteframe Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in folder.php in Siteframe CMS 3.2.3 and earlier, and Siteframe Beaumont 5.0.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2351 1 Webmanager-pro 1 Cms Webmanager-pro 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.
CVE-2008-3266 1 Softacid 1 Hotel Reservation System Multi 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.
CVE-2008-3267 1 Mojoscripts 1 Mojojobs 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.
CVE-2008-3291 1 Aprox 2 Aprox Cms Engine, Aproxengine 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2340 1 News Manager 1 News Manager 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
CVE-2008-3302 1 Tuxplanet 1 Bilboblog 2017-09-29 6.0 MEDIUM N/A
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.
CVE-2008-2337 1 Imgallery 1 Imgallery 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php and the (2) id_phot parameter to (b) popup/koment.php and (c) popup/opis.php in, different vectors than CVE-2006-3163.
CVE-2008-3307 1 Youtube Blog 1 Youtube Blog 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3306.
CVE-2008-3309 1 Digiappz 1 Digileave 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
CVE-2008-3310 1 Preproject 1 Pre Survey Poll 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-2336 1 68 Classifieds 1 68 Classifieds 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-2278 1 Freelanceauction 1 Freelance Auction Script 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action.
CVE-2008-2277 1 Cmsnx 1 Feedback And Rating Script 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
CVE-2008-3346 1 E-topbiz 1 Shopcart Dx 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2008-3351 1 Atomphotoblog 1 Atomphotoblog 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.
CVE-2008-3352 1 Nersoft 1 Live Music Plus 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.
CVE-2008-3355 1 Camera Life 1 Camera Life 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.
CVE-2008-2265 1 Emophp 1 Emo Realty Manager 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.
CVE-2008-3366 1 Pligg 1 Pligg Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.
CVE-2008-2263 1 Cmsnx 1 Automated Link Exchange Portal 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.
CVE-2008-2225 1 Gamecms 1 Gamecms Lite 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.
CVE-2008-3372 1 Greatclone 1 Getacoder Clone 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
CVE-2008-2223 1 Buyscripts 1 Vshare Youtube Clone 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
CVE-2008-3377 1 Brandon Tallent 1 Phptest 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
CVE-2008-3378 1 Fizzmedia Negativekarma 1 Fizzmedia 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
CVE-2008-3382 1 Mojoscripts 1 Mojoclassifieds 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.
CVE-2008-3383 1 Mojoscripts 1 Mojoauto 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.
CVE-2008-3386 1 Alstrasoft 1 Video Share Enterprise 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.
CVE-2008-3387 1 Phpfootball 1 Phpfootball 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.
CVE-2008-2222 1 Eqdkp 1 Eqdkp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.
CVE-2008-2197 1 Miniweb2 1 Blog Writer 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
CVE-2008-3403 1 Mojoscripts 1 Mojopersonals 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-3406 1 Phplinkat 1 Phplinkat 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-3412 1 Ecshop 1 Epshop 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.
CVE-2008-3413 1 Greatclone 1 Auction Platinum 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
CVE-2008-3414 1 Siteadmin 1 Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.
CVE-2008-3416 1 Icebb 1 Icebb 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.
CVE-2008-3417 1 Fipsasp 1 Fipscms Light 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.
CVE-2008-3418 1 Willo 1 Trio 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3419 1 Greatclone 1 Youtuber Clone 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.
CVE-2008-3420 1 Willo 1 Mobius Web Publishing Software 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.
CVE-2008-3445 1 Phpmyrealty 1 Phpmyrealty 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.
CVE-2008-3452 1 Endonesia 2 Calendar Module, Endonesia 2017-09-29 6.8 MEDIUM N/A
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.
CVE-2008-3484 1 Estoreaff 1 Estoreaff 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.
CVE-2008-3487 1 Phpauctions 1 Phpauction Gpl Enhanced 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3489 1 Phpx 1 Phpx 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.
CVE-2008-3490 1 E-topbiz 1 Online Dating 2017-09-29 6.5 MEDIUM N/A
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.
CVE-2008-3491 1 Scripts24 2 Ipost, Itgp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.
CVE-2008-2194 1 Deluxebb 1 Deluxebb 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.