Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,890 CVEs tagged with CWE-894,425 Critical, 8,379 High, 6,136 Medium, 949 Low, 1 Unrated.

CVE-2014-2655

Published Apr 2, 2014

SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3213

Published Apr 2, 2014

Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_pi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7349

Published Apr 1, 2014

Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter to news/send.php, (2) thread_id parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5640

Published Apr 1, 2014

Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1645

Published Mar 29, 2014

SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQ…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2559

Published Mar 27, 2014

SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2587

Published Mar 24, 2014

SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5276

Published Mar 21, 2014

SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5272

Published Mar 21, 2014

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3197

Published Mar 21, 2014

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to sha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1609

Published Mar 20, 2014

Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2339

Published Mar 19, 2014

Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1608

Published Mar 18, 2014

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a craf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4058

Published Mar 16, 2014

Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2043

Published Mar 13, 2014

SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3727

Published Mar 13, 2014

SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5117

Published Mar 12, 2014

SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2311

Published Mar 11, 2014

SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4467

Published Mar 11, 2014

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3961

Published Mar 11, 2014

SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6290

Published Mar 11, 2014

SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE:…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2318

Published Mar 11, 2014

SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2317

Published Mar 9, 2014

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these de…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 16,151-16,175 of 19,890 CVEsPage 647 of 796