Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2007-09-24 CVE-2007-5061 SQL Injection vulnerability in Clansphere 2007.4
SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action.
network
low complexity
clansphere CWE-89
7.5
2007-09-20 CVE-2007-5016 SQL Injection vulnerability in Insane Visions Onecms 2.4
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.
network
low complexity
insane-visions CWE-89
7.5
2007-09-19 CVE-2007-4984 SQL Injection vulnerability in Ktauber Stylesdemo 0.9.9
SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.
network
low complexity
ktauber phpbb CWE-89
7.5
2007-09-19 CVE-2007-4979 SQL Injection vulnerability in Kwsphp 1.0
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.
network
low complexity
kwsphp CWE-89
7.5
2007-09-18 CVE-2007-4966 SQL Injection vulnerability in Gforge
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.
network
gforge CWE-89
6.8
2007-09-18 CVE-2007-4956 SQL Injection vulnerability in Kwsphp 1.0
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
network
low complexity
kwsphp CWE-89
7.5
2007-09-18 CVE-2007-4953 SQL Injection vulnerability in Simpcms
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.
network
low complexity
simpcms CWE-89
7.5
2007-09-18 CVE-2007-4952 SQL Injection vulnerability in Omnistar Interactive Omnistar Article Manager
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
network
low complexity
omnistar-interactive CWE-89
7.5
2007-09-17 CVE-2007-4922 SQL Injection vulnerability in multiple products
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php.
network
low complexity
jeuxflash kwsphp CWE-89
6.5
2007-09-17 CVE-2007-4920 SQL Injection vulnerability in PHP Webquest PHP Webquest
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.
network
low complexity
php-webquest CWE-89
7.5