Vulnerabilities (CVE)

Filtered by CWE-89
Angry Yack Logo
Total 18012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19876 1 Br-automation 1 Industrial Automation Aprol 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
CVE-2019-19850 1 Typo3 1 Typo3 2024-11-21 6.5 MEDIUM 7.2 HIGH
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
CVE-2019-19846 1 Joomla 1 Joomla\! 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
CVE-2019-19740 1 Octeth 1 Oempro 2024-11-21 7.5 HIGH 9.8 CRITICAL
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CVE-2019-19734 1 Mfscripts 1 Yetishare 2024-11-21 6.5 MEDIUM 8.8 HIGH
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.
CVE-2019-19732 1 Mfscripts 1 Yetishare 2024-11-21 6.5 MEDIUM 7.2 HIGH
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.
CVE-2019-19650 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
CVE-2019-19649 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
CVE-2019-19608 1 Mitel 1 Micollab Audio\, Web \& Video Conferencing 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the registeredList.cgi page. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
CVE-2019-19607 1 Mitel 1 Micollab Audio\, Web \& Video Conferencing 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
CVE-2019-19499 1 Grafana 1 Grafana 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
CVE-2019-19292 1 Siemens 2 Sinvr 3 Central Control Server, Sinvr 3 Video Server 2024-11-21 6.5 MEDIUM 8.8 HIGH
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an SQL injection vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker could exploit this vulnerability to read or modify the CCS database and potentially execute administrative database operations or operating system commands.
CVE-2019-19286 1 Siemens 1 Xhq 2024-11-21 6.5 MEDIUM 7.2 HIGH
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if an attacker is able to modify content of particular web pages.
CVE-2019-19250 1 Opentrade Project 1 Opentrade 2024-11-21 7.5 HIGH 9.8 CRITICAL
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
CVE-2019-19209 1 Dolibarr 1 Dolibarr 2024-11-21 5.0 MEDIUM 7.5 HIGH
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2019-19207 1 Rconfig 1 Rconfig 2024-11-21 6.5 MEDIUM 8.8 HIGH
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVE-2019-19113 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 7.5 HIGH 9.8 CRITICAL
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
CVE-2019-19094 1 Hitachienergy 1 Esoms 2024-11-21 6.5 MEDIUM 7.6 HIGH
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
CVE-2019-19029 2 Linuxfoundation, Pivotal 2 Harbor, Vmware Harbor Registry 2024-11-21 6.5 MEDIUM 7.2 HIGH
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-19026 2 Linuxfoundation, Pivotal 2 Harbor, Vmware Harbor Registry 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
CVE-2019-19016 1 Titanhq 1 Webtitan 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.
CVE-2019-18890 2 Debian, Redmine 2 Debian Linux, Redmine 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
CVE-2019-18866 1 Blaauwproducts 1 Remote Kiln Control 2024-11-21 5.0 MEDIUM 7.5 HIGH
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
CVE-2019-18784 1 Salesagility 1 Suitecrm 2024-11-21 7.5 HIGH 9.8 CRITICAL
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
CVE-2019-18663 1 Isl 1 Arp-guard 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2019-18662 1 Youphptube 1 Youphptube 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.
CVE-2019-18646 1 Untangle 1 Ng Firewall 2024-11-21 6.5 MEDIUM 7.2 HIGH
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
CVE-2019-18622 3 Fedoraproject, Opensuse, Phpmyadmin 4 Fedora, Backports Sle, Leap and 1 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
CVE-2019-18464 1 Ipswitch 1 Moveit Transfer 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the datab ...

Show More

CVE-2019-18413 1 Typestack Class-validator Project 1 Typestack Class-validator 2024-11-21 7.5 HIGH 3.7 LOW
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious i ...

Show More

CVE-2019-18387 1 Hotel And Lodge Management System Project 1 Hotel And Lodge Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
CVE-2019-18344 1 Online Grading System Project 1 Online Grading System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).
CVE-2019-18234 1 Equinoxce 1 Control Expert 2024-11-21 7.5 HIGH 9.8 CRITICAL
Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.
CVE-2019-18229 1 Advantech 1 Wise-paas\/rmm 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.
CVE-2019-17647 1 Centreon 1 Centreon 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.
CVE-2019-17612 1 74cms 1 74cms 2024-11-21 6.5 MEDIUM 7.2 HIGH
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17602 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVE-2019-17580 1 Dormsystem Project 1 Dormsystem 2024-11-21 7.5 HIGH 9.8 CRITICAL
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2019-17553 1 Metinfo 1 Metinfo 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17552 1 Idreamsoft 1 Icms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.