Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12930 1 Tecnovision 1 Dlx Spot Player4 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
CVE-2017-12910 1 Nexusphp Project 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.
CVE-2017-12909 1 Nexusphp Project 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
CVE-2017-12908 1 Nexusphp Project 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr parameter.
CVE-2017-12776 1 Nexusphp Project 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.
CVE-2017-12774 1 Finecms Project 1 Finecms 2026-06-17 7.5 HIGH 9.8 CRITICAL
finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database
CVE-2017-12761 1 Webfile Explorer Project 1 Webfile Explorer 2026-06-17 5.0 MEDIUM 7.5 HIGH
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.
CVE-2017-12760 1 Ynetinteractive 1 Mobiketa 2026-06-17 6.5 MEDIUM 8.8 HIGH
Ynet Interactive - http://demo.ynetinteractive.com/mobiketa/ Mobiketa 4.0 is affected by: SQL Injection. The impact is: Code execution (remote).
CVE-2017-12759 1 Ynetinteractive 1 Soa School Management 2026-06-17 7.5 HIGH 9.8 CRITICAL
Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).
CVE-2017-12758 1 Joomlaextensions 1 Component Appointment 2026-06-17 7.5 HIGH 9.8 CRITICAL
https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.
CVE-2017-12757 1 Ambittechnologies 12 Itech B2b Script, Itech Business Networking Script, Itech Caregiver Script and 9 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).
CVE-2017-12731 1 Opwglobal 6 Sitesentinel Integra 100, Sitesentinel Integra 100 Firmware, Sitesentinel Integra 500 and 3 more 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via the input from the client.
CVE-2017-12729 1 Moxa 1 Softcms Lab View 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.
CVE-2017-12710 1 Advantech 1 Webaccess 2026-06-17 5.0 MEDIUM 7.5 HIGH
A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.
CVE-2017-12679 1 Nexusphp 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
CVE-2017-12650 1 Loginizer 1 Loginizer 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
CVE-2017-12585 1 Slims 1 Akasia 2026-06-17 6.5 MEDIUM 8.8 HIGH
SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.
CVE-2017-12567 1 Quest 3 K1000 As A Service, Kace Asset Management Appliance, Kace Systems Management Appliance 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
CVE-2017-12364 1 Cisco 1 Prime Service Catalog 2026-06-17 6.4 MEDIUM 6.5 MEDIUM
A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. Cisco Bug IDs: CSCvg30333.
CVE-2017-12302 1 Cisco 1 Unified Communications Domain Manager 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database. Cisco Bug IDs: CSCvf36682.