Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-8080

Disclosure Date: August 22, 2024 (last updated October 18, 2024)
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part of string leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-38348

Disclosure Date: June 18, 2024 (last updated October 10, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.
Attacker Value
Unknown

CVE-2024-38347

Disclosure Date: June 18, 2024 (last updated July 11, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.
Attacker Value
Unknown

CVE-2024-37803

Disclosure Date: June 18, 2024 (last updated July 16, 2024)
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
Attacker Value
Unknown

CVE-2024-37802

Disclosure Date: June 18, 2024 (last updated July 20, 2024)
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
Attacker Value
Unknown

CVE-2024-37800

Disclosure Date: June 18, 2024 (last updated July 06, 2024)
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
Attacker Value
Unknown

CVE-2022-46471

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter at /healthcare/Admin/consulting_detail.php.
Attacker Value
Unknown

CVE-2020-28074

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.