Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-12-13 CVE-2017-17567 SQL Injection vulnerability in Scubez Posty Readymade Classifieds
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
network
low complexity
scubez CWE-89
7.5
2017-12-11 CVE-2017-1606 SQL Injection vulnerability in IBM Financial Transaction Manager
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2017-12-11 CVE-2017-17111 SQL Injection vulnerability in Scubez Posty Readymade Classifieds 1.0
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
network
low complexity
scubez CWE-89
critical
9.8
2017-12-11 CVE-2017-17110 SQL Injection vulnerability in Techno - Portfolio Management Panel Project Techno - Portfolio Management Panel 20171116
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
network
low complexity
techno-portfolio-management-panel-project CWE-89
critical
9.8
2017-12-07 CVE-2017-1356 SQL Injection vulnerability in IBM Atlas Ediscovery Process Management
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2017-12-04 CVE-2017-17103 SQL Injection vulnerability in Fiyo CMS 2.0.7
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email].
network
low complexity
fiyo CWE-89
8.8
2017-12-04 CVE-2017-17102 SQL Injection vulnerability in Fiyo CMS 2.0.7
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
network
low complexity
fiyo CWE-89
7.5
2017-12-01 CVE-2017-16893 SQL Injection vulnerability in Piwigo
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior.
network
low complexity
piwigo CWE-89
6.5
2017-12-01 CVE-2017-10899 SQL Injection vulnerability in Ark-Web A-Reserve 3.8.6
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ark-web CWE-89
critical
9.8
2017-12-01 CVE-2017-10898 SQL Injection vulnerability in Ark-Web A-Member 3.8.6
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ark-web CWE-89
critical
9.8