Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2008-0326

Published Jan 17, 2008

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0327

Published Jan 17, 2008

SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0328

Published Jan 17, 2008

SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0291

Published Jan 16, 2008

SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0288

Published Jan 16, 2008

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0290

Published Jan 16, 2008

Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0286

Published Jan 16, 2008

SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0280

Published Jan 15, 2008

SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0281

Published Jan 15, 2008

SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0282

Published Jan 15, 2008

SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0173

Published Jan 15, 2008

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0253

Published Jan 15, 2008

SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0254

Published Jan 15, 2008

SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL comm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0255

Published Jan 15, 2008

SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0256

Published Jan 15, 2008

Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0262

Published Jan 15, 2008

SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0267

Published Jan 15, 2008

Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0270

Published Jan 15, 2008

SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0278

Published Jan 15, 2008

SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window actio…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0279

Published Jan 15, 2008

SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the catego…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0232

Published Jan 11, 2008

Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0219

Published Jan 10, 2008

SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0224

Published Jan 10, 2008

SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0185

Published Jan 9, 2008

SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0187

Published Jan 9, 2008

SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 19,426-19,450 of 19,915 CVEsPage 778 of 797