Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-7405 3 Adodb Project, Fedoraproject, Php 3 Adodb, Fedora, Php 2017-07-01 7.5 HIGH 9.8 CRITICAL
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
CVE-2016-6611 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 5.1 MEDIUM 8.1 HIGH
An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-9333 1 Moxa 1 Softcms 2017-06-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).
CVE-2017-1347 1 Ibm 1 Sterling B2b Integrator 2017-06-27 6.5 MEDIUM 8.8 HIGH
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126462.
CVE-2017-9759 1 Zenbership 1 Zenbership 2017-06-22 6.5 MEDIUM 8.8 HIGH
SQL Injection exists in admin/index.php in Zenbership 1.0.8 via the filters array parameter, exploitable by a privileged account.
CVE-2017-9463 1 Piwigo 1 Piwigo 2017-06-19 4.0 MEDIUM 6.5 MEDIUM
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The user_list_backend.php component is affected: values of the iDisplayStart & iDisplayLength parameters are not sanitized; these are used to construct a SQL query and retrieve a list of registered users into the application.
CVE-2016-2034 1 Arubanetworks 1 Clearpass 2017-06-14 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
CVE-2017-9436 1 Teampass 1 Teampass 2017-06-13 7.5 HIGH 9.8 CRITICAL
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
CVE-2017-9437 1 Openbravo 1 Openbravo Erp 2017-06-13 6.5 MEDIUM 8.8 HIGH
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
CVE-2016-7803 1 Cybozu 1 Garoon 2017-06-13 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.
CVE-2015-7346 1 Zcms Project 1 Zcms 2017-06-12 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ZCMS 1.1.
CVE-2017-9449 1 Bigtreecms 1 Bigtree Cms 2017-06-12 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.
CVE-2017-9443 1 Bigtreecms 1 Bigtree Cms 2017-06-09 6.5 MEDIUM 8.8 HIGH
** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and core\admin\modules\developer\packages\install\process.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files."
CVE-2016-5939 1 Ibm 1 Kenexa Lms On Cloud 2017-06-08 6.5 MEDIUM 6.3 MEDIUM
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-9435 1 Dolibarr 1 Dolibarr 2017-06-08 7.5 HIGH 9.8 CRITICAL
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).
CVE-2016-10379 1 Virtuemart 1 Virtuemart 2017-06-08 6.5 MEDIUM 7.2 HIGH
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
CVE-2016-10378 1 E107 1 E107 2017-06-07 6.5 MEDIUM 7.2 HIGH
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
CVE-2017-9360 1 Websitebaker 1 Websitebaker 2017-06-06 7.5 HIGH 9.8 CRITICAL
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.
CVE-2017-9427 1 Bigtreecms 1 Bigtree Cms 2017-06-06 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/developer/modules/designer/ and the injection is visible at admin/dashboard/vitals-statistics/integrity/check/?external=true.
CVE-2017-7236 1 Netapp 1 Oncommand Unified Manager Core Package 2017-06-02 5.0 MEDIUM 7.5 HIGH
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-4905 1 Wp-olivecart 2 Olivecart, Olivecartpro 2017-05-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-6195 1 Ipswitch 2 Moveit Dmz, Moveit Transfer 2017 2017-05-26 7.5 HIGH 9.8 CRITICAL
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
CVE-2016-4893 1 Setucocms Project 1 Setucocms 2017-05-23 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-5527 1 Tibco 2 Spotfire Analytics Platform For Aws, Spotfire Server 2017-05-23 4.0 MEDIUM 6.5 MEDIUM
TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.
CVE-2017-8796 1 Accellion 1 File Transfer Appliance 2017-05-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
CVE-2017-8789 1 Accellion 1 File Transfer Appliance 2017-05-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVE-2017-6557 1 Xirrus 1 Arrayos 2017-05-17 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-7886 1 Dolibarr 1 Dolibarr 2017-05-15 7.5 HIGH 9.8 CRITICAL
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
CVE-2017-8377 1 Genixcms 1 Genixcms 2017-05-10 6.5 MEDIUM 8.8 HIGH
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
CVE-2017-2120 1 Wbce 1 Wbce Cms 2017-05-03 6.0 MEDIUM 7.2 HIGH
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-1218 1 Cybozu 1 Garoon 2017-04-25 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
CVE-2016-2566 1 Samsung 2 Galaxy S6, Galaxy S6 Firmware 2017-04-21 7.5 HIGH 9.8 CRITICAL
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.
CVE-2017-7879 1 Flatcore 1 Flatcore-cms 2017-04-21 5.0 MEDIUM 7.5 HIGH
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
CVE-2017-7878 1 Flatcore 1 Flatcore-cms 2017-04-21 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
CVE-2017-7628 1 Smart Related Articles Project 1 Smart Related Articles 2017-04-20 7.5 HIGH 9.8 CRITICAL
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
CVE-2017-7719 1 Web-dorado 1 Spider Event Calendar 2017-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
CVE-2015-7564 1 Teampass 1 Teampass 2017-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.
CVE-2016-4337 1 Ktools 1 Photostore 2017-04-19 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.
CVE-2017-7581 1 News System Project 1 News System 2017-04-13 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
CVE-2016-10096 1 Genixcms 1 Genixcms 2017-04-11 7.5 HIGH 7.3 HIGH
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
CVE-2016-9087 1 Exponentcms 1 Exponent Cms 2017-04-04 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.
CVE-2016-9020 1 Exponentcms 1 Exponent Cms 2017-04-04 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
CVE-2017-7290 1 Xoops 1 Xoops 2017-04-03 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
CVE-2016-9019 1 Exponentcms 1 Exponent Cms 2017-04-01 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
CVE-2016-7789 1 Exponentcms 1 Exponent Cms 2017-04-01 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
CVE-2016-7788 1 Exponentcms 1 Exponent Cms 2017-04-01 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2016-7780 1 Exponentcms 1 Exponent Cms 2017-03-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
CVE-2016-7781 1 Exponentcms 1 Exponent Cms 2017-03-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.
CVE-2016-7782 1 Exponentcms 1 Exponent Cms 2017-03-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.
CVE-2016-7783 1 Exponentcms 1 Exponent Cms 2017-03-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.