Vulnerabilities (CVE)

Filtered by CWE-89
Total 20717 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4620 1 Mrbs 1 Mrbs 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
CVE-2008-4617 3 Joomla, Mambo-foundation, Pyxicom 3 Joomla, Mambo, Actualite 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4613 1 Portalapp 1 Portalapp 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
CVE-2008-4611 1 Php Arsivimiz 1 Php Ziyaretci Defteri 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHP Arsivimiz Php Ziyaretci Defteri allows remote attackers to execute arbitrary SQL commands via the sayfa parameter.
CVE-2008-4606 1 Ip Reg 1 Ip Reg 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id parameter to vlanedit.php. NOTE: the vlanview.php and vlandel.php vectors are already covered by CVE-2007-6579.
CVE-2008-4605 1 Cafeengine 1 Easycafeengine 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php.
CVE-2008-4604 1 Cafeengine 1 Easycafeengine 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
CVE-2008-4603 1 Igaming 1 Cms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search_games action.
CVE-2008-4599 1 Mosaic Commerce 1 Mosaic Commerce 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-4590 1 Stash 1 Stash 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to admin/login.php and (2) the post parameter to admin/news.php.
CVE-2008-4574 1 Aspindir 1 Ayco Okul Portali 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
CVE-2008-4573 1 Aspindir 1 Munzursoft Web Portal W3 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2008-4570 1 Real-estate-scripts 1 Real-estate-scripts 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-4569 1 Xigla 1 Absolute Poll Manager Xe 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2008-4534 1 Ec-cube 1 Ec-cube 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-4531 1 Drupal 1 Brilliant Gallery 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338.
CVE-2008-4527 1 Php-fusion 1 Recepies Module 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information.
CVE-2008-4525 1 Ampjuke 1 Ampjuke 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.
CVE-2008-4524 1 Adaptcms 1 Adaptcms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.
CVE-2008-4523 1 Ip Reg 1 Ip Reg 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.