2231 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2018-25161
Warranty Tracking System Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName, and txtPhone POST parameters in SearchCustomer.php. Attackers can submit crafted SQL statements using UNION SELECT to extract sensitive database information including usernames, database names, and version details.

CVE-2018-25179
Gumbo CMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the language parameter. Attackers can send POST requests to the settings endpoint with crafted SQL payloads in the language parameter to extract sensitive database information including usernames, databases, and version details.

CVE-2018-25182
Silurus Classifieds Script Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table names and sensitive information from the database.

CVE-2018-25194
Nominas Web Database
8.8
HIGH
EPSS
0.2%
2018 CWE-22 1 PoC

Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payloads to extract database information including usernames, database names, and version details.

CVE-2018-25163
BitZoom Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.

CVE-2018-25206
KomSeo Cart Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or error-based injection techniques.

CVE-2018-3879
SmartThings Hub STH-ETH-250 Web Database
8.8
HIGH
EPSS
0.2%
2018 1 PoC

An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON injection which in turn leads to a SQL injection in the video-core database. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2018-25210
Ticaret V4 Database
8.8
HIGH
EPSS
0.1%
2018 CWE-79 1 PoC

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database.

CVE-2018-25173
Rmedia SMS Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and sensitive database data.

CVE-2018-25176
Alive Parish Database
8.8
HIGH
EPSS
0.1%
2018 CWE-352 1 PoC

Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the images/uploaded directory for remote code execution.

CVE-2018-25189
Data Center Audit Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database names, and version details.

CVE-2018-25202
SAT CFDI Database
8.8
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection payloads to extract sensitive data or compromise the application.

CVE-2018-25196
ServerZilla Web Database
8.8
HIGH
EPSS
0.3%
2018 CWE-89 1 PoC

ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to reset.php with malicious email values containing SQL operators to bypass authentication and extract sensitive database information.

CVE-2018-25204
Library CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username field to manipulate database queries and gain unauthorized access.

CVE-2018-25197
PlayJoom Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with option=com_playjoom&view=genre&catid=[SQL] to extract sensitive database information including usernames, databases, and version details.

CVE-2018-25205
ASP.NET jVideo Kit Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information using boolean-based blind or error-based techniques.

CVE-2018-25188
Webiness Inventory Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the order parameter. Attackers can send POST requests to the WsModelGrid.php endpoint with crafted SQL payloads to extract sensitive database information including usernames, databases, and version details.

CVE-2018-25185
Wecodex Restaurant CMS Web Database
8.8
HIGH
EPSS
0.0%
2018 CWE-89 1 PoC

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind techniques to extract sensitive database information.

CVE-2018-25208
qdPM Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[CommentCreatedTo] parameters to execute arbitrary SQL queries and retrieve sensitive data.

CVE-2018-25195
Wecodex Hotel CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.