Vulnerabilities (CVE)

Filtered by CWE-89
Total 20766 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4215 1 Oneorzero 1 Aims 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.
CVE-2011-4113 2 Drupal, Earl Miles 2 Drupal, Views 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
CVE-2011-4094 1 Jara Project 1 Jara 2026-06-16 7.5 HIGH 9.8 CRITICAL
Jara 1.6 has a SQL injection vulnerability.
CVE-2011-4066 1 Sir 1 Gnuboard 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
CVE-2011-4026 1 Xia Zuojie 1 Nexusphp 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2011-3989 1 Hiroyuki Oyama 1 Dbd\ 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2011-3988 1 Lockon 1 Ec-cube 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2011-3838 1 Wuzly 1 Wuzly 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Wuzly 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to fp.php, (2) epage parameter to newpage.php, (3) epost parameter to newpost.php, and (4) username parameter to login.php in admin/; or the (5) username parameter to mobile/login.php.
CVE-2011-3831 1 Sitracker 1 Support Incident Tracker 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitrary SQL commands via an uploaded file with a crafted file name.
CVE-2011-3688 1 Sonexis 1 Conferencemanager 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Sonexis ConferenceManager 9.3.14.0 allow remote attackers to execute arbitrary SQL commands via (1) the g parameter to Conference/Audio/AudioResourceContainer.asp or (2) the txtConferenceID parameter to Login/HostLogin.asp.
CVE-2011-3615 1 Simplemachines 1 Smf 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information.
CVE-2011-3584 1 Guidestar 1 Wec Discussion Forum 2026-06-16 7.5 HIGH 9.8 CRITICAL
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
CVE-2011-3583 1 Typo3 1 Typo3 2026-06-16 7.5 HIGH 9.8 CRITICAL
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.
CVE-2011-3394 1 Myrephp 1 Myre Real Estate Software 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2011-3340 1 Atcom 1 Netvolution 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.
CVE-2011-3197 1 Gplhost 1 Domain Technologie Control 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shared/inc/forms/domain_info.php. NOTE: CVE-2011-3197 has been SPLIT due to findings by different researchers. CVE-2011-5272 has been assigned for the vps_note parameter to dtcadmin/logPushlet.php vector.
CVE-2011-3130 1 Wordpress 1 Wordpress 2026-06-16 7.5 HIGH N/A
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.
CVE-2011-2944 1 Megalab 1 The Uploader 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2011-2936 1 Elgg 1 Elgg 2026-06-16 7.5 HIGH 9.8 CRITICAL
Elgg through 1.7.10 has a SQL injection vulnerability
CVE-2011-2930 1 Rubyonrails 2 Rails, Ruby On Rails 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.