16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-12507
moni:tools Database
8.8
HIGH
EPSS
0.7%
2020 CWE-89 1 PoC

In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS.

CVE-2020-36999
Elaniin CMS Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.

CVE-2020-37141
AMSS++ Web Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.

CVE-2020-37057
Online-Exam-System Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

CVE-2020-37110
60CycleCMS Web Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents. This issue does not involve cross-site scripting.

CVE-2020-13568
phpGACL Web Database
8.8
HIGH
EPSS
0.2%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter parent_id leads to a SQL injection.

CVE-2020-37151
phpMyChat Plus Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by crafting malicious payloads in the username field.

CVE-2020-37083
PHP Address Book Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint.

CVE-2020-14735
Database - Enterprise Edition Database
8.8
HIGH
EPSS
0.0%
2020 1 PoC

Vulnerability in the Scheduler component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Scheduler executes to compromise Scheduler. While the vulnerability is in Scheduler, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Scheduler. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3

CVE-2020-37033
Infor Storefront B2B Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database information.

CVE-2020-14862
Universal Work Queue Web Database
8.8
HIGH
EPSS
4.4%
2020 1 PoC

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3 - 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-2902
VM VirtualBox Database
8.8
HIGH
EPSS
0.2%
2020 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integr

CVE-2020-13566
phpGACL Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_group.php, when the POST parameter action is “Delete”, the POST parameter delete_group leads to a SQL injection.

CVE-2020-37051
Online-Exam-System Web Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.

CVE-2020-13567
OpenEMR Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-36945
WebDamn User Registration & Login System with User Panel Database
8.8
HIGH
EPSS
0.4%
2020 CWE-89 1 PoC

WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel.

CVE-2020-37163
QuickDate Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user credentials, database name, and system version.

CVE-2018-25167
Billetterie Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicious SQL code through the login POST parameter to extract database information including usernames, passwords, and system credentials.

CVE-2018-25175
Alienor Web Libre Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the identifiant parameter. Attackers can submit crafted POST requests to index.php with SQL injection payloads in the identifiant field to extract sensitive database information including usernames, databases, and version details.

CVE-2018-25172
Pedidos Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to the ajax/load_proveedores.php endpoint with crafted SQL payloads to extract sensitive database information including schema names and table structures.