Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-09 CVE-2022-38273 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38274 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38275 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38276 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38277 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38278 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38279 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38280 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38281 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
network
low complexity
jflyfox CWE-89
7.2
2022-09-09 CVE-2022-38282 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
network
low complexity
jflyfox CWE-89
7.2