Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-12-13 CVE-2017-17632 SQL Injection vulnerability in Responsive Events and Movie Ticket Booking Script Project Responsive Events and Movie Ticket Booking Script 3.2.1
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
9.8
2017-12-13 CVE-2017-17631 SQL Injection vulnerability in Multireligion Responsive Matrimonial Project Multireligion Responsive Matrimonial 4.7.2
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
network
low complexity
multireligion-responsive-matrimonial-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17630 SQL Injection vulnerability in Yoga Class Script Project Yoga Class Script 1.0
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
network
low complexity
yoga-class-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17629 SQL Injection vulnerability in Secure E-Commerce Script Project Secure E-Commerce Script 2.0.1
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
network
low complexity
secure-e-commerce-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17628 SQL Injection vulnerability in Responsive Realestate Script Project Responsive Realestate Script 3.2
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
network
low complexity
responsive-realestate-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17627 SQL Injection vulnerability in Readymade Video Sharing Script Project Readymade Video Sharing Script 3.2
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
network
low complexity
readymade-video-sharing-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17626 SQL Injection vulnerability in Readymade PHP Classified Script Project Readymade PHP Classified Script 3.3
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
network
low complexity
readymade-php-classified-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17625 SQL Injection vulnerability in on Demand Marketplace Script Project on Demand Marketplace Script 1.0
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
network
low complexity
on-demand-marketplace-script-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17624 SQL Injection vulnerability in PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce 1.0
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
network
low complexity
php-multivendor-ecommerce-project CWE-89
critical
9.8
2017-12-13 CVE-2017-17623 SQL Injection vulnerability in Opensource Classified ADS Script Project Opensource Classified ADS Script 3.2
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
network
low complexity
opensource-classified-ads-script-project CWE-89
critical
9.8