Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-12-13 CVE-2017-17601 SQL Injection vulnerability in CAB Booking Script Project CAB Booking Script 1.0
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
network
low complexity
cab-booking-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17600 SQL Injection vulnerability in Basic B2B Script Project Basic B2B Script 2.0.8
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
network
low complexity
basic-b2b-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17599 SQL Injection vulnerability in Advance Online Learning Management Script Project Advance Online Learning Management Script 3.1
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.
9.8
2017-12-13 CVE-2017-17598 SQL Injection vulnerability in Affiliate MLM Script Project Affiliate MLM Script 1.0
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
network
low complexity
affiliate-mlm-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17597 SQL Injection vulnerability in Nearbuy Clone Script Project Nearbuy Clone Script 3.2
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
network
low complexity
nearbuy-clone-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17596 SQL Injection vulnerability in Entrepreneur JOB Portal Script Project Entrepreneur JOB Portal Script 2.0.6
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
network
low complexity
entrepreneur-job-portal-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17595 SQL Injection vulnerability in Beauty Parlour Booking Script Project Beauty Parlour Booking Script 1.0
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
network
low complexity
beauty-parlour-booking-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17594 SQL Injection vulnerability in Domainsale PHP Script Project Domainsale PHP Script 1.0
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
network
low complexity
domainsale-php-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17592 SQL Injection vulnerability in Website Auction Marketplace Project Website Auction Marketplace 2.0.5
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
network
low complexity
website-auction-marketplace-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17591 SQL Injection vulnerability in Realestate Crowdfunding Script Project Realestate Crowdfunding Script 2.7.2
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
network
low complexity
realestate-crowdfunding-script-project CWE-89
critical
9.8