Total
16151 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-18796 | 1 Library Management System Project | 1 Library Management System | 2024-11-21 | N/A |
Library Management System 1.0 has SQL Injection via the "Search for Books" screen. | ||||
CVE-2018-18795 | 1 School Event Management System Project | 1 School Event Management System | 2024-11-21 | N/A |
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | ||||
CVE-2018-18792 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. | ||||
CVE-2018-18791 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. | ||||
CVE-2018-18790 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.) | ||||
CVE-2018-18789 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | ||||
CVE-2018-18788 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.) | ||||
CVE-2018-18787 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | ||||
CVE-2018-18786 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | ||||
CVE-2018-18785 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | ||||
CVE-2018-18784 | 1 Zzcms | 1 Zzcms | 2024-11-21 | N/A |
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.) | ||||
CVE-2018-18763 | 1 Saltos | 1 Saltos | 2024-11-21 | N/A |
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | ||||
CVE-2018-18761 | 1 Saltos | 1 Saltos | 2024-11-21 | 9.8 Critical |
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | ||||
CVE-2018-18758 | 1 Open Faculty Evaluation System Project | 1 Open Faculty Evaluation System | 2024-11-21 | N/A |
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757. | ||||
CVE-2018-18757 | 1 Open Faculty Evaluation System Project | 1 Open Faculty Evaluation System | 2024-11-21 | N/A |
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758. | ||||
CVE-2018-18755 | 1 K-iwi | 1 K-iwi | 2024-11-21 | 9.8 Critical |
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter. | ||||
CVE-2018-18705 | 1 Phptpoint | 1 Hospital Management System | 2024-11-21 | N/A |
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php. | ||||
CVE-2018-18704 | 1 Phptpoint | 1 Pharmacy Management System | 2024-11-21 | N/A |
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | ||||
CVE-2018-18702 | 1 Icmsdev | 1 Icms | 2024-11-21 | N/A |
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | ||||
CVE-2018-18619 | 1 Advanced Comment System Project | 1 Advanced Comment System | 2024-11-21 | N/A |
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued. |