Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2022-36545

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
Attacker Value
Unknown

CVE-2022-36544

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
Attacker Value
Unknown

CVE-2022-36543

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
Attacker Value
Unknown

CVE-2022-36542

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated November 28, 2024)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Attacker Value
Unknown

CVE-2021-27320

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Attacker Value
Unknown

CVE-2021-27319

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
Attacker Value
Unknown

CVE-2021-27315

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Attacker Value
Unknown

CVE-2021-27316

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
Attacker Value
Unknown

CVE-2021-27314

Disclosure Date: March 05, 2021 (last updated February 22, 2025)
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.