| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. |
| Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. |
| FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. |
| FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. |
| Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. |
| SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971. |
| PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. |
| The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. |
| Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. |
| Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. |
| Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. |
| SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/. |
| Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. |
| Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. |
| Child Care Script 1.0 has SQL Injection via the /list city parameter. |
| Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. |
| Doctor Search Script 1.0 has SQL Injection via the /list city parameter. |
| Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. |
| Event Search Script 1.0 has SQL Injection via the /event-list city parameter. |
| Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. |