16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2015-7297
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2015 5 PoCs

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

CVE-2015-4816
Software Genérico Database
N/A
UNKNOWN
EPSS
4.0%
2015 4 PoCs

Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.

CVE-2007-1696
Software Genérico Database
N/A
UNKNOWN
EPSS
2.5%
2007 1 PoC

SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.

CVE-2007-6551
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2007 1 PoC

SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2014-4235
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2014 3 PoCs

Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect integrity via unknown vectors.

CVE-2015-0487
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0472.

CVE-2015-0468
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2015 1 PoC

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2014-10023
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.1%
2014 1 PoC

Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.

CVE-2015-7383
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbitrary web script or HTML via the (1) adminUserName, (2) pathToMYSQL, (3) databaseStructureFile, or (4) pathToBibutils parameter to install.php or the (5) adminUserName parameter to update.php.

CVE-2007-2339
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.0%
2007 2 PoCs

Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.

CVE-2014-0437
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2014 2 PoCs

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

CVE-2015-7564
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2015 1 PoC

Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.

CVE-2015-4820
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4907.

CVE-2015-0398
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Unspecified vulnerability in the Siebel Life Sciences component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Clinical Trip Report.

CVE-2015-2623
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2, and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0, allows remote attackers to affect integrity via unknown vectors related to Java Server Faces.

CVE-2007-2211
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.

CVE-2007-4810
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php.

CVE-2007-6602
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2007 1 PoC

SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.

CVE-2007-1289
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.0%
2007 1 PoC

SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.

CVE-2007-0347
Software Genérico Database
N/A
UNKNOWN
EPSS
2.3%
2007 1 PoC

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.