Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-19113

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-23763

Disclosure Date: April 09, 2021 (last updated February 22, 2025)
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
Attacker Value
Unknown

CVE-2020-36003

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
Attacker Value
Unknown

CVE-2020-24115

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.