Vulnerabilities (CVE)

Filtered by CWE-89
Angry Yack Logo
Total 18012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11452 1 Whatsns 1 Whatsns 2024-11-21 6.5 MEDIUM 7.2 HIGH
whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection.
CVE-2019-11451 1 Whatsns 1 Whatsns 2024-11-21 6.5 MEDIUM 7.2 HIGH
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
CVE-2019-11450 1 Whatsns 1 Whatsns 2024-11-21 7.5 HIGH 9.8 CRITICAL
whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
CVE-2019-11448 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 10.0 HIGH 9.8 CRITICAL
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
CVE-2019-11363 1 Prophecyinternational 1 Snare Central 2024-11-21 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
CVE-2019-11362 1 Rocboss 1 Rocboss 2024-11-21 7.5 HIGH 9.8 CRITICAL
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI.
CVE-2019-11196 1 Vpcsbd 1 Integrated University Management System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).
CVE-2019-11057 1 Vtiger 1 Vtiger Crm 2024-11-21 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
CVE-2019-10916 1 Siemens 4 Simatic Pcs 7, Simatic Wincc, Simatic Wincc \(tia Portal\) and 1 more 2024-11-21 9.0 HIGH 8.8 HIGH
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Upd 9), SIMATIC WinCC (TIA Portal) V15 (All versions < V15.1 Upd 3), SIMATIC WinCC Runtime Professional ...

Show More

CVE-2019-10913 1 Sensiolabs 1 Symfony 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
CVE-2019-10910 2 Drupal, Sensiolabs 2 Drupal, Symfony 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
CVE-2019-10866 1 10web 1 Form Maker 2024-11-21 7.5 HIGH 9.8 CRITICAL
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
CVE-2019-10852 1 Computrols 1 Computrols Building Automation Software 2024-11-21 6.5 MEDIUM 8.8 HIGH
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
CVE-2019-10766 1 Pixie Project 1 Pixie 2024-11-21 7.5 HIGH 9.8 CRITICAL
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
CVE-2019-10763 1 Pimcore 1 Pimcore 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
CVE-2019-10762 1 Medoo 1 Medoo 2024-11-21 7.5 HIGH 9.8 CRITICAL
columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
CVE-2019-10757 1 Knexjs 1 Knex 2024-11-21 7.5 HIGH 9.8 CRITICAL
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
CVE-2019-10752 1 Sequelizejs 1 Sequelize 2024-11-21 7.5 HIGH 9.8 CRITICAL
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
CVE-2019-10749 1 Sequelizejs 1 Sequelize 2024-11-21 7.5 HIGH 9.8 CRITICAL
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
CVE-2019-10748 1 Sequelizejs 1 Sequelize 2024-11-21 7.5 HIGH 9.8 CRITICAL
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
CVE-2019-10708 1 S-cms 1 S-cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
CVE-2019-10707 1 Mkcms Project 1 Mkcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
CVE-2019-10692 1 Codecabin 1 Wp Go Maps 2024-11-21 7.5 HIGH 9.8 CRITICAL
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
CVE-2019-10687 1 Kbpublisher 1 Kbpublisher 2024-11-21 7.5 HIGH 9.8 CRITICAL
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-10671 1 Librenms 1 Librenms 2024-11-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.
CVE-2019-10664 1 Domoticz 1 Domoticz 2024-11-21 7.5 HIGH 9.8 CRITICAL
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
CVE-2019-10663 1 Grandstream 2 Ucm6204, Ucm6204 Firmware 2024-11-21 6.5 MEDIUM 8.8 HIGH
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
CVE-2019-10653 1 Hsycms 1 Hsycms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
CVE-2019-10262 1 Bluecms Project 1 Bluecms 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.
CVE-2019-10232 1 Teclib-edition 1 Gestionnaire Libre De Parc Informatique 2024-11-21 7.5 HIGH 9.8 CRITICAL
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
CVE-2019-10208 1 Postgresql 1 Postgresql 2024-11-21 6.5 MEDIUM 8.8 HIGH
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
CVE-2019-10141 2 Openstack, Redhat 3 Ironic-inspector, Enterprise Linux, Openstack 2024-11-21 6.4 MEDIUM 8.3 HIGH
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Be ...

Show More

CVE-2019-10123 1 Ais 2 Esel-server, Logistic Software 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.
CVE-2019-1010259 1 Saltstack 2 Salt 2018, Salt 2019 2024-11-21 7.5 HIGH 9.8 CRITICAL
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
CVE-2019-1010248 1 I-doit 1 I-doit 2024-11-21 7.5 HIGH 9.8 CRITICAL
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
CVE-2019-1010201 1 Jeesite 1 Jeesite 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticated. The fixed version is: 4.0 and later.
CVE-2019-1010191 1 Marginalia Project 1 Marginalia 2024-11-21 7.5 HIGH 9.8 CRITICAL
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.
CVE-2019-1010153 1 Zzcms 1 Zzcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
CVE-2019-1010148 1 Zzcms 1 Zzcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
CVE-2019-1010104 1 Techytalk 1 Quick Chat 2024-11-21 7.5 HIGH 9.8 CRITICAL
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.