Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,889 CVEs tagged with CWE-894,425 Critical, 8,378 High, 6,136 Medium, 949 Low, 1 Unrated.

CVE-2006-0205

Published Jan 13, 2006

Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the logi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0192

Published Jan 13, 2006

SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0159

Published Jan 10, 2006

SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this inf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0160

Published Jan 10, 2006

SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0115

Published Jan 9, 2006

Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0123

Published Jan 9, 2006

Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0074

Published Jan 4, 2006

SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4617

Published Dec 31, 2005

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4632

Published Dec 31, 2005

SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4711

Published Dec 31, 2005

SQL injection vulnerability in Neocrome Land Down Under (LDU) 801 allows remote attackers to execute arbitrary SQL commands via an HTTP Referer header. NOTE: the provenance of th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4515

Published Dec 23, 2005

SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vend…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4500

Published Dec 22, 2005

SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this inform…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4478

Published Dec 22, 2005

Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) gu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4495

Published Dec 22, 2005

SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this iss…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4380

Published Dec 20, 2005

Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4382

Published Dec 20, 2005

SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4349

Published Dec 19, 2005

SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4315

Published Dec 17, 2005

SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4263

Published Dec 15, 2005

SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4228

Published Dec 14, 2005

Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_nu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4232

Published Dec 14, 2005

SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4244

Published Dec 14, 2005

SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4246

Published Dec 14, 2005

SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 19,801-19,825 of 19,889 CVEsPage 793 of 796