Total
14524 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-11623 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb. A remote background administrator privilege user (or a user with permission to manage configuration siteweb) could exploit the vulnerability to obtain database sensitive information. | |||||
CVE-2019-11622 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre. | |||||
CVE-2019-11621 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a user with permission to manage network configuration) could exploit the vulnerability to obtain database sensitive information. | |||||
CVE-2019-11620 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_add_titre. | |||||
CVE-2019-11619 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or a user with permission to manage configuration analytics) could exploit the vulnerability to obtain database sensitive information. | |||||
CVE-2019-11614 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information. | |||||
CVE-2019-11613 | 1 Doorgets | 1 Doorgets Cms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sensitive information. | |||||
CVE-2019-11600 | 1 Openproject | 1 Openproject | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access. | |||||
CVE-2019-11567 | 1 Aikcms | 1 Aikcms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an admin/page/system/nav.php?del= URI. | |||||
CVE-2019-11518 | 1 Sem-cms | 1 Semcms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete. | |||||
CVE-2019-11512 | 1 Contao | 1 Contao | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. | |||||
CVE-2019-11469 | 1 Zohocorp | 1 Manageengine Applications Manager | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature. | |||||
CVE-2019-11452 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection. | |||||
CVE-2019-11451 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
whatsns 4.0 allows index.php?inform/add.html qid SQL injection. | |||||
CVE-2019-11450 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection. | |||||
CVE-2019-11448 | 1 Zohocorp | 1 Manageengine Applications Manager | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file. | |||||
CVE-2019-11363 | 1 Prophecyinternational | 1 Snare Central | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter. | |||||
CVE-2019-11362 | 1 Rocboss | 1 Rocboss | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI. | |||||
CVE-2019-11196 | 1 Vpcsbd | 1 Integrated University Management System | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings). | |||||
CVE-2019-11057 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands. |