Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown

CVE-2023-0529

Disclosure Date: January 27, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-219598 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0528

Disclosure Date: January 27, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/abc.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219597 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0516

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.
Attacker Value
Unknown

CVE-2023-0515

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-219335.
Attacker Value
Unknown

CVE-2023-0324

Disclosure Date: January 16, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218426 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-44401

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
Attacker Value
Unknown

CVE-2022-43050

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-43061

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-41537

Disclosure Date: October 18, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-42142

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.