Show filters
41 Total Results
Displaying 21-30 of 41
Sort by:
Attacker Value
Unknown
CVE-2023-1432
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be launched remotely. VDB-223214 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27073
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
0
Attacker Value
Unknown
CVE-2023-24647
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
0
Attacker Value
Unknown
CVE-2023-24646
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2023-24197
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
0
Attacker Value
Unknown
CVE-2023-24195
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
0
Attacker Value
Unknown
CVE-2023-24194
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
0
Attacker Value
Unknown
CVE-2023-24192
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
0
Attacker Value
Unknown
CVE-2023-24191
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
0
Attacker Value
Unknown
CVE-2020-29297
Disclosure Date: January 20, 2023 (last updated November 02, 2023)
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
0