Show filters
1,391 Total Results
Displaying 31-40 of 1,391
Sort by:
Attacker Value
Very High

CVE-2021-37808

Disclosure Date: October 27, 2021 (last updated February 23, 2025)
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.
Attacker Value
Very High

CVE-2021-42224

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
Attacker Value
Very High

CVE-2021-41647

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
Attacker Value
Very High

CVE-2021-36624

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Attacker Value
Very High

CVE-2021-36621

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
Attacker Value
Unknown

CVE-2020-23630

Disclosure Date: January 11, 2021 (last updated February 22, 2025)
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
Attacker Value
Unknown

CVE-2021-3018

Disclosure Date: January 05, 2021 (last updated February 22, 2025)
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
Attacker Value
Unknown

CVE-2020-35847

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Attacker Value
Unknown

CVE-2020-29574

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Attacker Value
Very Low

CVE-2020-11530

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.