Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1000003 1 Filedownload Project 1 Filedownload 2017-03-29 7.5 HIGH 9.8 CRITICAL
Blind SQL Injection in filedownload v1.4 wordpress plugin
CVE-2016-1000116 1 Huge-it 1 Portfolio Gallery Manager 2017-03-28 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2017-6492 1 Admidio 1 Admidio 2017-03-25 9.0 HIGH 7.2 HIGH
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
CVE-2017-3899 1 Mcafee 1 Advanced Threat Defense 2017-03-23 4.0 MEDIUM 6.5 MEDIUM
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
CVE-2017-6550 1 Kinsey 1 Infor-lawson 2017-03-23 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.
CVE-2016-9728 1 Ibm 1 Qradar Security Information And Event Manager 2017-03-08 5.0 MEDIUM 7.5 HIGH
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
CVE-2016-10204 1 Zoneminder 1 Zoneminder 2017-03-07 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2017-5218 1 Sagecrm 1 Sagecrm 2017-03-02 6.5 MEDIUM 8.8 HIGH
A SQL Injection issue was discovered in SageCRM 7.x before 7.3 SP3. The AP_DocumentUI.asp web resource includes Utilityfuncs.js when the file is opened or viewed. This file crafts a SQL statement to identify the database that is to be in use with the current user's session. The database variable can be populated from the URL, and when supplied non-expected characters, can be manipulated to obtain access to the underlying database. The /CRM/CustomPages/ACCPAC/AP_DocumentUI.asp?SID=<VALID-SID>&database=1';WAITFOR DELAY '0:0:5'-- URI is a Proof of Concept.
CVE-2016-9993 1 Ibm 1 Kenexa Lcms Premier 2017-03-01 6.5 MEDIUM 7.1 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
CVE-2016-9994 1 Ibm 1 Kenexa Lcms Premier 2017-03-01 6.5 MEDIUM 7.1 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.
CVE-2016-9992 1 Ibm 1 Kenexa Lcms Premier 2017-03-01 6.5 MEDIUM 7.1 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
CVE-2016-8341 1 Ecava 1 Integraxor 2017-03-01 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands.
CVE-2016-3694 1 Modified 1 Ecommerce Shopsoftware 2017-02-23 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.
CVE-2017-6065 1 Metalgenix 1 Genixcms 2017-02-23 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
CVE-2016-5952 1 Ibm 1 Kenexa Lcms Premier 2017-02-08 6.5 MEDIUM 8.8 HIGH
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-5879 1 Exponentcms 1 Exponent Cms 2017-02-08 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src.
CVE-2016-8928 1 Ibm 1 Kenexa Lms 2017-02-07 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-8929 1 Ibm 1 Kenexa Lms 2017-02-07 5.5 MEDIUM 5.4 MEDIUM
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-8930 1 Ibm 1 Kenexa Lms 2017-02-07 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-9416 1 Mybb 2 Merge System, Mybb 2017-02-05 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-9402 1 Mybb 2 Merge System, Mybb 2017-02-05 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-8974 1 Mybb 2 Merge System, Mybb 2017-02-05 7.5 HIGH 10.0 CRITICAL
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-5598 1 Eclinicalworks 1 Patient Portal 2017-02-01 5.0 MEDIUM 7.5 HIGH
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.
CVE-2017-5517 1 Metalgenix 1 Genixcms 2017-01-27 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.
CVE-2017-5519 1 Metalgenix 1 Genixcms 2017-01-27 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2017-5347 1 Metalgenix 1 Genixcms 2017-01-27 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
CVE-2017-5345 1 Metalgenix 1 Genixcms 2017-01-27 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
CVE-2016-0769 1 Elfden 1 Eshop Plugin 2017-01-26 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
CVE-2017-5575 1 Metalgenix 1 Genixcms 2017-01-26 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.
CVE-2017-5574 1 Metalgenix 1 Genixcms 2017-01-26 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.
CVE-2017-5569 1 Eclinicalworks 1 Patient Portal 2017-01-26 7.5 HIGH 9.8 CRITICAL
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
CVE-2017-5570 1 Eclinicalworks 1 Patient Portal 2017-01-26 6.5 MEDIUM 8.8 HIGH
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
CVE-2016-10114 1 Awebsupport 1 Aweb Cart Watching System For Virtuemart 2017-01-11 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
CVE-2015-0699 1 Cisco 1 Unified Communications Domain Manager 2017-01-06 5.0 MEDIUM N/A
SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut21563.
CVE-2016-1000117 1 Huge-it 1 Slideshow 2017-01-06 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2015-3980 1 Sap 1 Customer Relationship Management 2017-01-03 7.5 HIGH N/A
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVE-2015-1889 1 Ibm 1 Infosphere Biginsights 2017-01-03 6.5 MEDIUM N/A
The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an import of a certain Hive table definition with the HCAT_SYNC_OBJECTS procedure.
CVE-2014-9089 2 Debian, Mantisbt 2 Debian Linux, Mantisbt 2017-01-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.
CVE-2013-7349 1 Raoul Proenca 1 Gnew 2016-12-31 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parameter to posts/edit.php, or (3) user_email parameter to users/password.php or (4) users/register.php. NOTE: these issues were SPLIT from CVE-2013-5640 due to differences in researchers and disclosure dates.
CVE-2013-7242 1 Zenphoto 1 Zenphoto 2016-12-31 6.5 MEDIUM N/A
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.
CVE-2013-7375 1 Php-fusion 1 Php-fusion 2016-12-31 7.5 HIGH N/A
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.
CVE-2013-5003 1 Phpmyadmin 1 Phpmyadmin 2016-12-31 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote authenticated users to execute arbitrary SQL commands via (1) the scale parameter to pmd_pdf.php or (2) the pdf_page_number parameter to schema_export.php.
CVE-2015-3345 1 Phplist Integration Project 1 Phplist Integration 2016-12-31 6.5 MEDIUM N/A
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."
CVE-2013-5640 1 Raoul Proenca 1 Gnew 2016-12-31 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or (5) thread_id parameter to posts/add.php. NOTE: this issue was SPLIT due to differences in researchers and disclosure dates. CVE-2013-7349 already covers the news_id parameter to news/send.php, user_email parameter to users/register.php, and thread_id to posts/edit.php vectors.
CVE-2015-2066 1 Dlguard 1 Dlguard 2016-12-31 7.5 HIGH N/A
SQL injection vulnerability in DLGuard 4.5 allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.
CVE-2013-7175 1 Avanset 1 Visual Certexam Manager 2016-12-31 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.
CVE-2015-6299 1 Cisco 1 Unity Connection 2016-12-29 6.5 MEDIUM N/A
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.
CVE-2015-4222 1 Cisco 1 Unified Communications Manager Im And Presence Service 2016-12-28 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.
CVE-2015-4233 1 Cisco 1 Unified Meetingplace 2016-12-28 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.
CVE-2015-4208 1 Cisco 1 Webex Meeting Center 2016-12-28 7.5 HIGH N/A
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.