Show filters
332 Total Results
Displaying 121-130 of 332
Sort by:
Attacker Value
Unknown

CVE-2023-1378

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This vulnerability affects unknown code of the file paypalsuccess.php of the component POST Parameter Handler. The manipulation of the argument cusid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222904.
Attacker Value
Unknown

CVE-2023-1311

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This affects an unknown part of the file large.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222699.
Attacker Value
Unknown

CVE-2023-1301

Disclosure Date: March 09, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this issue is some unknown functionality of the file deleteorder.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-222662 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1041

Disclosure Date: February 26, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221799.
Attacker Value
Unknown

CVE-2022-45527

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
Attacker Value
Unknown

CVE-2022-45526

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
Attacker Value
Unknown

CVE-2017-20150

Disclosure Date: December 28, 2022 (last updated February 24, 2025)
A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The name of the patch is f1644b1d3502e5aa5284f31ea80d2623817f4d42. It is recommended to apply a patch to fix this issue. The identifier VDB-216989 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-45990

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
Attacker Value
Unknown

CVE-2022-42098

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
Attacker Value
Unknown

CVE-2021-41433

Disclosure Date: September 27, 2022 (last updated February 24, 2025)
SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.