Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,274 CVEs tagged with CWE-894,544 Critical, 8,504 High, 6,245 Medium, 980 Low, 1 Unrated.

CVE-2007-1163

Published Mar 2, 2007

SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1166

Published Mar 2, 2007

SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1171

Published Mar 2, 2007

SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7025

Published Feb 23, 2007

SQL injection vulnerability in admin/config.php in Bookmark4U 2.0 and 2.1 allows remote attackers to inject arbitrary SQL command via the sqlcmd parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1026

Published Feb 21, 2007

SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1034

Published Feb 21, 2007

SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0984

Published Feb 16, 2007

SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0985

Published Feb 16, 2007

SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0875

Published Feb 12, 2007

SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0789

Published Feb 6, 2007

SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0794

Published Feb 6, 2007

SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0642

Published Jan 31, 2007

SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0582

Published Jan 30, 2007

SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0520

Published Jan 26, 2007

SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0527

Published Jan 26, 2007

SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the R…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0350

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0196

Published Jan 11, 2007

SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6848

Published Dec 31, 2006

SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO, possibly related to the Password parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6880

Published Dec 31, 2006

Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newn…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6912

Published Dec 31, 2006

SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7231

Published Dec 31, 2006

SQL injection vulnerability in display.asp in Civica Software Civica allows remote attackers to execute arbitrary SQL commands via the Entry parameter. NOTE: the provenance of th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7232

Published Dec 31, 2006

sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMA…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6747

Published Dec 27, 2006

SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 20,076-20,100 of 20,274 CVEsPage 804 of 811