Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-0939

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection.This issue affects Online Services Software: before 1.17.
Attacker Value
Unknown

CVE-2022-1840

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1839

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(2)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. The attack can be initiated remotely but it requires authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1838

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2022-1837

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.
Attacker Value
Unknown

CVE-2021-36723

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
Attacker Value
Unknown

CVE-2021-36722

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
Attacker Value
Unknown

CVE-2021-27999

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database.
Attacker Value
Unknown

CVE-2021-28000

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields.
Attacker Value
Unknown

CVE-2021-3278

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.