Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2005-11-22 CVE-2005-3744 SQL Injection vulnerability in PHPcomasy 0.7.4
SQL injection vulnerability in index.php in phpComasy 0.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
phpcomasy CWE-89
7.5
2005-11-19 CVE-2005-3686 SQL Injection vulnerability in Newsboard Unclassified Newsboard
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.
network
low complexity
newsboard CWE-89
7.5
2005-11-17 CVE-2005-3646 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.
network
low complexity
phpadsnew phppgads CWE-89
7.5
2005-11-16 CVE-2005-3553 SQL Injection vulnerability in PHPkit
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).
network
low complexity
phpkit CWE-89
7.5
2005-11-16 CVE-2005-3543 SQL Injection vulnerability in Phorum
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
network
phorum CWE-89
6.8
2005-10-30 CVE-2005-3365 SQL Injection vulnerability in Codeworx Technologies Dcp-Portal
Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3) the year parameter in calendar.php, and the (4) cid parameter to index.php.
network
low complexity
codeworx-technologies CWE-89
7.5
2005-10-27 CVE-2005-3325 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.
network
low complexity
acid secureideas CWE-89
7.5
2005-09-24 CVE-2005-3046 SQL Injection vulnerability in PHPmyfaq 1.5.1
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.
network
phpmyfaq CWE-89
6.8
2005-09-20 CVE-2005-2983 SQL Injection vulnerability in Oracle Reports 1.00
SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.
network
low complexity
oracle CWE-89
7.5
2005-06-16 CVE-2005-2035 SQL Injection vulnerability in Cool Cafe Chat Cool Cafe Chat 1.2.1
SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.
network
low complexity
cool-cafe-chat CWE-89
7.5