Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-6575 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.
CVE-2017-6576 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.
CVE-2017-6573 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.
CVE-2017-6572 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.
CVE-2017-6571 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.
CVE-2017-6570 1 Mail-masta Project 1 Mail-masta 2019-03-19 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.
CVE-2017-5346 1 Genixcms 1 Genixcms 2019-03-15 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
CVE-2019-9762 1 Phpshe 1 Phpshe 2019-03-14 7.5 HIGH 9.8 CRITICAL
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
CVE-2015-4592 1 Eclinicalworks 1 Population Health 2019-03-14 6.5 MEDIUM 8.8 HIGH
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.
CVE-2017-6097 1 Mail-masta Project 1 Mail-masta 2019-03-13 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.
CVE-2017-6088 1 Eyesofnetwork 1 Eyesofnetwork 2019-03-13 9.0 HIGH 7.2 HIGH
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
CVE-2017-6098 1 Mail-masta Project 1 Mail-masta 2019-03-13 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.
CVE-2017-6095 1 Mail-masta Project 1 Mail-masta 2019-03-13 7.5 HIGH 9.8 CRITICAL
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.
CVE-2017-6096 1 Mail-masta Project 1 Mail-masta 2019-03-13 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.
CVE-2015-1434 1 Mylittleforum 1 My Little Forum 2019-03-13 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.
CVE-2017-6013 1 Intelliants 1 Subrion Cms 2019-03-12 7.5 HIGH 9.8 CRITICAL
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.
CVE-2015-7568 1 Yeager 1 Yeager Cms 2019-03-12 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
CVE-2008-6594 1 Network-publishing 1 Rdf Newsfeed Export 2019-03-12 7.5 HIGH N/A
SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2019-9693 1 Cmsmadesimple 1 Cms Made Simple 2019-03-12 6.5 MEDIUM 8.8 HIGH
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
CVE-2017-10842 1 Basercms 1 Basercms 2019-03-12 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-7390 1 Testlink 1 Testlink 2019-03-11 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
CVE-2015-7569 1 Yeager 1 Yeager Cms 2019-03-11 7.5 HIGH 8.8 HIGH
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
CVE-2008-2451 1 Inmedias 1 Statistics 2019-03-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2018-17420 1 Zrlog 1 Zrlog 2019-03-08 6.5 MEDIUM 7.2 HIGH
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.
CVE-2018-16809 1 Dolibarr 1 Dolibarr 2019-03-08 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
CVE-2018-17416 1 Zzcms 1 Zzcms 2019-03-08 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
CVE-2018-17415 1 Zzcms 1 Zzcms 2019-03-08 6.5 MEDIUM 8.8 HIGH
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
CVE-2018-17414 1 Zzcms 1 Zzcms 2019-03-08 6.5 MEDIUM 8.8 HIGH
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
CVE-2018-17412 1 Zzcms 1 Zzcms 2019-03-08 7.5 HIGH 9.8 CRITICAL
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
CVE-2019-9568 1 Wpmudev 1 Forminator Contact Form\, Poll \& Quiz Builder 2019-03-07 4.0 MEDIUM 6.5 MEDIUM
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
CVE-2016-8027 1 Mcafee 1 Epolicy Orchestrator 2019-03-07 7.5 HIGH 10.0 CRITICAL
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
CVE-2019-9626 1 Phpshe 1 Phpshe 2019-03-07 7.5 HIGH 9.8 CRITICAL
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
CVE-2018-18450 1 Pbootcms 1 Pbootcms 2019-03-07 7.5 HIGH 9.8 CRITICAL
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
CVE-2019-9594 1 Bluecms Project 1 Bluecms 2019-03-07 7.5 HIGH 9.8 CRITICAL
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
CVE-2018-6329 1 Unitrends 1 Backup 2019-03-07 10.0 HIGH 9.8 CRITICAL
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.
CVE-2019-9615 1 Ofcms Project 1 Ofcms 2019-03-07 6.5 MEDIUM 7.2 HIGH
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
CVE-2018-8734 1 Nagios 1 Nagios Xi 2019-03-05 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
CVE-2019-9566 1 Flarumchina 1 Flarumchina 2019-03-05 7.5 HIGH 9.8 CRITICAL
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
CVE-2018-6382 1 Mantisbt 1 Mantisbt 2019-03-04 2.1 LOW 3.3 LOW
** DISPUTED ** MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parameter in a request to the 127.0.0.1 IP address. NOTE: the vendor disputes the significance of this report because server.php is intended to execute arbitrary SQL statements on behalf of authenticated users from 127.0.0.1, and the issue does not have an authentication bypass.
CVE-2018-7033 2 Debian, Schedmd 2 Debian Linux, Slurm 2019-02-28 7.5 HIGH 9.8 CRITICAL
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
CVE-2018-8057 1 Westernbridgegroup 1 Razor 2019-02-28 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.
CVE-2018-7802 1 Schneider-electric 2 Evlink Parking, Evlink Parking Firmware 2019-02-28 6.5 MEDIUM 8.8 HIGH
A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.
CVE-2019-9047 1 Fizzday 1 Gorose 2019-02-25 7.5 HIGH 9.8 CRITICAL
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
CVE-2016-1000271 1 Dthdevelopment 1 Dt Register 2019-02-22 7.5 HIGH 9.8 CRITICAL
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.
CVE-2017-18362 1 Connectwise 1 Manageditsync 2019-02-22 7.5 HIGH 9.8 CRITICAL
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
CVE-2019-8421 1 Bagesoft 1 Bagecms 2019-02-20 6.5 MEDIUM 7.2 HIGH
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
CVE-2019-8393 1 Hotels Server Project 1 Hotels Server 2019-02-20 7.5 HIGH 9.8 CRITICAL
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
CVE-2019-8360 1 Themerig 1 Find A Place Cms Directory 2019-02-20 7.5 HIGH 9.8 CRITICAL
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
CVE-2019-8422 1 Pbootcms 1 Pbootcms 2019-02-19 6.5 MEDIUM 7.2 HIGH
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.
CVE-2019-8423 1 Zoneminder 1 Zoneminder 2019-02-19 7.5 HIGH 9.8 CRITICAL
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.