Show filters
95 Total Results
Displaying 11-20 of 95
Sort by:
Attacker Value
Unknown

CVE-2024-32167

Disclosure Date: June 10, 2024 (last updated June 13, 2024)
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.
Attacker Value
Unknown

CVE-2024-5745

Disclosure Date: June 07, 2024 (last updated August 07, 2024)
A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/product/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-267414 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-5636

Disclosure Date: June 05, 2024 (last updated June 12, 2024)
A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file report/index.php. The manipulation of the argument procduct leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-267092.
Attacker Value
Unknown

CVE-2024-5635

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument txtsearch leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-267091.
Attacker Value
Unknown

CVE-2024-25217

Disclosure Date: February 14, 2024 (last updated October 24, 2024)
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
Attacker Value
Unknown

CVE-2024-0423

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file dishes.php. The manipulation of the argument res_id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250442 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0247

Disclosure Date: January 05, 2024 (last updated January 12, 2024)
A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249778 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-45344

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-45343

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-45342

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.