Filtered by CWE-89
Total 16382 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-22781 1 Etherpad 1 Etherpad 2024-11-21 7.5 High
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
CVE-2020-22669 2 Debian, Owasp 2 Debian Linux, Owasp Modsecurity Core Rule Set 2024-11-21 9.8 Critical
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
CVE-2020-22425 1 Centreon 1 Centreon 2024-11-21 8.8 High
Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.
CVE-2020-22226 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
CVE-2020-22225 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
CVE-2020-22223 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
CVE-2020-22212 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
CVE-2020-22211 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
CVE-2020-22210 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CVE-2020-22209 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CVE-2020-22208 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CVE-2020-22206 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
CVE-2020-22205 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
CVE-2020-22204 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
CVE-2020-22203 1 Phpcms 1 Phpcms 2024-11-21 9.8 Critical
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
CVE-2020-22199 1 Phpcms 1 Phpcms 2024-11-21 9.8 Critical
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
CVE-2020-22198 1 Dedecms 1 Dedecms 2024-11-21 9.8 Critical
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
CVE-2020-22175 1 Phpgurukul 1 Hospital Management System 2024-11-21 7.5 High
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22174 1 Phpgurukul 1 Hospital Management System 2024-11-21 7.5 High
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22173 1 Phpgurukul 1 Hospital Management System 2024-11-21 7.5 High
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.