Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-10013 1 Awpcp 1 Another Wordpress Classifieds Plugin 2017-09-08 7.5 HIGH N/A
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
CVE-2014-10017 1 Welcart 1 E-commerce 2017-09-08 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2) switch parameter in the usces_itemedit page to wp-admin/admin.php.
CVE-2014-10020 1 Tecorange 1 Simple E-document 2017-09-08 7.5 HIGH N/A
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2014-10023 1 Topicsviewer 1 Topicsviewer 2017-09-08 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.
CVE-2014-10029 1 Fluxbb 1 Fluxbb 2017-09-08 7.5 HIGH N/A
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.
CVE-2014-10032 1 Scriptbrasil 1 Taboada Macronews 2017-09-08 6.5 MEDIUM N/A
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
CVE-2014-10033 1 Oscommerce 1 Online Merchant 2017-09-08 6.5 MEDIUM N/A
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute arbitrary SQL commands via the zID parameter in a list action.
CVE-2012-6654 1 Zpanelcp 1 Zpanel 2017-09-08 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685.
CVE-2014-10038 1 Domphp 1 Domphp 2017-09-08 7.5 HIGH N/A
SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.
CVE-2015-8334 1 Huawei 2 Vcn500, Vcn500 Firmware 2017-09-07 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.
CVE-2015-7517 1 Labwebdesigns 1 Double Opt-in For Download 2017-09-07 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
CVE-2017-14069 1 Nexusphp 1 Nexusphp 2017-09-07 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
CVE-2017-14145 1 Helpdezk 1 Helpdezk 2017-09-06 7.5 HIGH 9.8 CRITICAL
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
CVE-2016-10509 1 Opencart 1 Opencart 2017-09-06 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
CVE-2016-1000123 1 Huge-it 1 Video Gallery 2017-09-06 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVE-2016-1000125 1 Huge-it 1 Huge-it Catalog 2017-09-06 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2017-09-06 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2017-14076 1 Nexusphp 1 Nexusphp 2017-09-05 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
CVE-2016-8582 1 Alienvault 2 Open Source Security Information And Event Management, Unified Security Management 2017-09-03 7.5 HIGH 9.8 CRITICAL
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
CVE-2016-8025 1 Mcafee 1 Virusscan Enterprise 2017-09-03 6.0 MEDIUM 6.2 MEDIUM
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
CVE-2015-2866 1 Grandstream 2 Gxv3611 Hd, Gxv3611 Hd Firmware 2017-09-03 7.5 HIGH N/A
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL commands by attempting to establish a TELNET session with a crafted username.
CVE-2017-10839 1 Seopanel 1 Seo Panel 2017-09-01 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-5742 1 Sixapart 2 Movable Type, Movable Type Open Source 2017-09-01 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-5344 1 Dotcms 1 Dotcms 2017-09-01 7.5 HIGH 9.8 CRITICAL
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
CVE-2016-1446 1 Cisco 1 Webex Meetings Server 2017-09-01 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
CVE-2014-9558 1 Smartcms 1 Smartcms 2017-08-31 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in SmartCMS v.2.
CVE-2017-11475 1 Glpi-project 1 Glpi 2017-08-29 6.5 MEDIUM 8.8 HIGH
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
CVE-2014-5109 1 Fonality 1 Trixbox 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.
CVE-2014-4824 1 Ibm 1 Qradar Security Information And Event Manager 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-4424 1 Apple 1 Os X Server 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-7189 1 Iscripts 1 Autohoster 2017-08-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.
CVE-2014-4313 1 Epicor 1 Epicor Procurement 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in Epicor Procurement before 7.4 SP2 allows remote attackers to execute arbitrary SQL commands via the User field.
CVE-2013-6936 1 Mybb 1 Ajax Forum Stat 2017-08-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
CVE-2014-4034 1 Aas9 1 Zerocms 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
CVE-2013-6983 1 Cisco 1 Unified Presence Server 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615.
CVE-2013-7092 1 Mcafee 1 Email Gateway 2017-08-29 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) event_id, (3) reason, (4) events_order, (5) emailstatus_order, or (6) emailstatus_col JSON keys.
CVE-2013-7187 1 Ncrafts 1 Formcraft 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2013-7192 1 Etoshop 1 Dynamic Biz Website Builder Quickweb 2017-08-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.
CVE-2014-2238 1 Mantisbt 1 Mantisbt 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id parameter.
CVE-2014-1204 1 Tableausoftware 1 Tableau Server 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.
CVE-2014-3446 1 Bss 1 Continuity Cms 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.
CVE-2013-7193 1 Etoshop 1 C2c Forward Auction Creator 2017-08-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.
CVE-2014-3366 1 Cisco 1 Unified Communications Manager 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.
CVE-2013-7216 1 Etoshop 1 Classifieds Creator 2017-08-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.
CVE-2014-3339 1 Cisco 2 Unified Communications Domain Manager, Unified Presence Server 2017-08-29 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290.
CVE-2014-3326 1 Cisco 1 Security Manager 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
CVE-2014-1466 1 Csp Mysql User Manager Project 1 Csp Mysql User Manager 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in CSP MySQL User Manager 2.3 allows remote attackers to execute arbitrary SQL commands via the login field of the login page.
CVE-2013-7278 1 Naxtech 1 Cms Afroditi 2017-08-29 7.5 HIGH N/A
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp.
CVE-2014-3336 1 Cisco 1 Unity Connection 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.
CVE-2014-3138 1 Xerox 1 Docushare 2017-08-29 6.5 MEDIUM N/A
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are obtained from third party information.