CVE-2017-5151

CVSS v3 Score
7.3
High
CVSS v2 Score
7.5
High

Vulnerability Description

An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.

CVSS:7.3(High)

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

CWE-892015
CVSS:7.3(High)

SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.

CWE-892016
CVSS:7.3(High)

SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CWE-892016
CVSS:7.3(High)

A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSC...

CWE-892016
CVSS:7.3(High)

connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.

CWE-892019
CVSS:7.3(High)

The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.

CWE-892019