957 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2019-25260
OXID eShop Web Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

CVE-2019-25539
202CMS Web Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind injection techniques to extract sensitive database information.

CVE-2019-25684
OpenDocMan Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

CVE-2019-25461
Ticaret Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send POST requests to the ajax/productsFilterSearch endpoint with malicious 'q' values using time-based blind SQL injection techniques to extract sensitive database information.

CVE-2019-25672
PilusCart Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.

CVE-2019-25517
Hazir Haber Sitesi Scripti Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send requests to haberarsiv.php with malicious cid values using UNION-based injection to extract sensitive database information or modify database contents.

CVE-2019-25536
Netartmedia PHP Real Estate Agency Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to extract sensitive database information or manipulate database queries.

CVE-2019-25530
uHotelBooking System Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using time-based blind SQL injection techniques to extract sensitive database information.

CVE-2019-25506
FreeSMS Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to /pages/crc_handler.php?method=login to authenticate as any known user and subsequently modify their password via the profile update function.

CVE-2019-25496
osCommerce Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append boolean-based SQL injection payloads to extract sensitive database information.

CVE-2019-25640
Inout Article Base CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

CVE-2019-25493
Homey BNB (Airbnb Clone Script) Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract sensitive database information.

CVE-2019-25499
Simple Job Script Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.

CVE-2019-25635
Zeeways Matrimony CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the profile_list endpoint. Attackers can inject SQL code via the up_cast, s_mother, and s_religion parameters to extract sensitive database information using time-based or error-based techniques.

CVE-2019-25642
Bootstrapy CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of contact-submit.php, the post-id parameter of post-new-submit.php, and the thread-id parameter to extract sensitive database information or cause denial of service.

CVE-2019-25525
Inout EasyRooms Ultimate Edition Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the guests parameter. Attackers can send POST requests to the search/rentals endpoint with malicious SQL payloads to bypass authentication, extract sensitive data, or modify database contents.

CVE-2019-25522
XooGallery Web Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id parameter. Attackers can send GET requests to photo.php with malicious photo_id values to extract sensitive data, bypass authentication, or modify database contents.

CVE-2019-25440
WebIncorp ERP Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter. Attackers can send GET requests to product_detail.php with malicious prod_id values to extract sensitive database information.

CVE-2019-25669
qdPM Database
8.8
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.

CVE-2019-25439
NoviSmart CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.