Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,239 CVEs tagged with CWE-894,532 Critical, 8,498 High, 6,235 Medium, 973 Low, 1 Unrated.

CVE-2006-1501

Published Mar 30, 2006

SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1423

Published Mar 28, 2006

SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number para…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1360

Published Mar 23, 2006

Multiple SQL injection vulnerabilities in MusicBox 2.3 Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) type, or (3) show parameter to (a) index…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1330

Published Mar 21, 2006

Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) artic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1278

Published Mar 19, 2006

SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1049

Published Mar 7, 2006

Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unkn…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1018

Published Mar 7, 2006

SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1006

Published Mar 6, 2006

Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0959

Published Mar 2, 2006

SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0961

Published Mar 2, 2006

SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter. NOTE: this product has also bee…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0772

Published Feb 19, 2006

SQL injection vulnerability in Hitachi Business Logic - Container 02-03 through 03-00-/B on Windows, and 03-00 through 03-00-/B on Linux, allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0750

Published Feb 18, 2006

SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0692

Published Feb 15, 2006

Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0602

Published Feb 8, 2006

Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0586

Published Feb 8, 2006

Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_J…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0510

Published Feb 1, 2006

SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0412

Published Jan 25, 2006

SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0413

Published Jan 25, 2006

Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) lim…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0403

Published Jan 25, 2006

Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0318

Published Jan 19, 2006

SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0269

Published Jan 18, 2006

Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln#…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0249

Published Jan 18, 2006

SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0240

Published Jan 18, 2006

Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possib…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0199

Published Jan 13, 2006

SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 20,126-20,150 of 20,239 CVEsPage 806 of 810