Show filters
1,013 Total Results
Displaying 1-10 of 1,013
Sort by:
Attacker Value
Very High

CVE-2021-40578

Disclosure Date: December 07, 2021 (last updated February 23, 2025)
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.
Attacker Value
Very High

CVE-2021-42668

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.
Attacker Value
Very High

CVE-2021-41649

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Attacker Value
Very High

CVE-2021-43420

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
Attacker Value
Very High

CVE-2021-44655

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.
Attacker Value
Very High

CVE-2021-42671

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
Attacker Value
Very High

CVE-2021-42665

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
Attacker Value
Very High

CVE-2021-42667

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.
Attacker Value
Very High

CVE-2021-41646

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
Attacker Value
Very High

CVE-2021-41648

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.