Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated November 28, 2024)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Attacker Value
Unknown

CVE-2021-27320

Disclosure Date: March 24, 2021 (last updated November 28, 2024)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Attacker Value
Unknown

CVE-2021-27319

Disclosure Date: March 24, 2021 (last updated November 28, 2024)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
Attacker Value
Unknown

CVE-2021-27315

Disclosure Date: March 24, 2021 (last updated November 28, 2024)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Attacker Value
Unknown

CVE-2021-27316

Disclosure Date: March 24, 2021 (last updated November 28, 2024)
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
Attacker Value
Unknown

CVE-2021-27314

Disclosure Date: March 05, 2021 (last updated November 28, 2024)
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
Attacker Value
Unknown

CVE-2021-27317

Disclosure Date: March 01, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
Attacker Value
Unknown

CVE-2021-27318

Disclosure Date: March 01, 2021 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.
Attacker Value
Unknown

CVE-2021-27124

Disclosure Date: February 18, 2021 (last updated November 28, 2024)
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
Attacker Value
Unknown

CVE-2020-29283

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.