Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2007-12-11 CVE-2007-6311 SQL Injection vulnerability in Falt4 CMS Falt4 Extreme RC4 10.9.2007
SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter.
network
low complexity
falt4-cms CWE-89
7.5
2007-12-10 CVE-2007-6292 SQL Injection vulnerability in Mwopen E-Commerce 0/1.4
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
mwopen CWE-89
7.5
2007-12-10 CVE-2007-6291 SQL Injection vulnerability in Xigla Absolute Banner Manager.Net 4.0
SQL injection vulnerability in abm.aspx in Xigla Absolute Banner Manager .NET 4.0 allows remote attackers to execute arbitrary SQL commands via the z parameter.
network
low complexity
xigla CWE-89
7.5
2007-12-10 CVE-2007-6288 SQL Injection vulnerability in Tecnick.Com Tcexam
Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
tecnick-com CWE-89
7.5
2007-12-07 CVE-2007-6275 SQL Injection vulnerability in Bcoos
SQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter, a different vector than CVE-2007-6266.
network
low complexity
bcoos CWE-89
7.5
2007-12-07 CVE-2007-6272 SQL Injection vulnerability in Joomla 1.5Rc3
Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search action to the com_search component.
network
low complexity
joomla CWE-89
7.5
2007-12-07 CVE-2007-6269 SQL Injection vulnerability in Xigla Absolute News Manager.Net 5.1
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
network
low complexity
xigla CWE-89
7.5
2007-12-07 CVE-2007-6266 SQL Injection vulnerability in Bcoos 1.0.10
Multiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to modules/arcade/index.php in a show_stats action, or the lid parameter to (2) modules/myalbum/ratephoto.php or (3) modules/mylinks/ratelink.php, different vectors than CVE-2007-5104.
network
low complexity
bcoos CWE-89
7.5
2007-12-05 CVE-2007-6240 SQL Injection vulnerability in Snitz Communications Snitz Forums 2000 3.4.06
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.
network
low complexity
snitz-communications CWE-89
7.5
2007-12-05 CVE-2007-6014 SQL Injection vulnerability in Beehive Forum Beehive Forum
SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter.
network
low complexity
beehive-forum CWE-89
7.5