Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2005-11-26 CVE-2005-3817 SQL Injection vulnerability in Softbiz web Hosting Directory Script
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an unspecified parameter to the search module.
network
low complexity
softbiz CWE-89
7.5
2005-11-22 CVE-2005-3748 SQL Injection vulnerability in Tru-Zone Nukeet 3.0/3.1/3.2
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.
network
low complexity
tru-zone CWE-89
7.5
2005-11-22 CVE-2005-3744 SQL Injection vulnerability in PHPcomasy 0.7.4
SQL injection vulnerability in index.php in phpComasy 0.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
phpcomasy CWE-89
7.5
2005-11-19 CVE-2005-3686 SQL Injection vulnerability in Newsboard Unclassified Newsboard
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.
network
low complexity
newsboard CWE-89
7.5
2005-11-17 CVE-2005-3646 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
network
low complexity
phpadsnew phppgads CWE-89
7.5
2005-11-16 CVE-2005-3553 SQL Injection vulnerability in PHPkit
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).
network
low complexity
phpkit CWE-89
7.5
2005-11-16 CVE-2005-3543 SQL Injection vulnerability in Phorum
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
network
phorum CWE-89
6.8
2005-10-30 CVE-2005-3365 SQL Injection vulnerability in Codeworx Technologies Dcp-Portal
Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3) the year parameter in calendar.php, and the (4) cid parameter to index.php.
network
low complexity
codeworx-technologies CWE-89
7.5
2005-10-27 CVE-2005-3325 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.
network
low complexity
acid secureideas CWE-89
7.5
2005-09-24 CVE-2005-3046 SQL Injection vulnerability in PHPmyfaq 1.5.1
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.
network
phpmyfaq CWE-89
6.8