Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2007-5402

Published Jan 9, 2008

Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0147

Published Jan 9, 2008

SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the u…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0154

Published Jan 9, 2008

SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0157

Published Jan 9, 2008

SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0159

Published Jan 9, 2008

SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0133

Published Jan 8, 2008

Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0137

Published Jan 8, 2008

PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0138

Published Jan 8, 2008

PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0139

Published Jan 8, 2008

Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0142

Published Jan 8, 2008

Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecifi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0144

Published Jan 8, 2008

PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6671

Published Jan 8, 2008

SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0129

Published Jan 8, 2008

SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name par…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0130

Published Jan 8, 2008

SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6670

Published Jan 8, 2008

SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0099

Published Jan 8, 2008

Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unsp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6647

Published Jan 4, 2008

SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6656

Published Jan 4, 2008

SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6658

Published Jan 4, 2008

SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6663

Published Jan 4, 2008

SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6664

Published Jan 4, 2008

SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6665

Published Jan 4, 2008

SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6666

Published Jan 4, 2008

SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6667

Published Jan 4, 2008

SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6639

Published Jan 4, 2008

SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewdir action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 19,451-19,475 of 19,915 CVEsPage 779 of 797