NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
34649  CVE-2014-7228  Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an archive, does not delete parameters from $_GET and $_POST when it is cleansing $_REQUEST, but later accesses $_GET and $_POST using the getQueryParam function, which allows remote attackers to bypass encryption and execute arbitrary code via a command message that extracts a crafted archive.    7.5  High  2017-01-19  2016-05-09  View
35929  CVE-2014-9175  SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the table_id parameter in a get_wdtable action to wp-admin/admin-ajax.php.    7.5  High  2017-01-19  2014-12-03  View
40537  CVE-2013-5120  SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.    7.5  High  2017-01-18  2013-08-14  View
44121  CVE-2012-2306  SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-19  2012-09-11  View
47449  CVE-2009-0109  SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2009-01-29  View

Page 2954 of 17672, showing 5 records out of 88360 total, starting on record 14766, ending on 14770

Actions