Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown

CVE-2022-36544

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
Attacker Value
Unknown

CVE-2022-36543

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
Attacker Value
Unknown

CVE-2022-36542

Disclosure Date: August 26, 2022 (last updated October 08, 2023)
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
Attacker Value
Unknown

CVE-2022-28601

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
Attacker Value
Unknown

CVE-2022-28986

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
Attacker Value
Unknown

CVE-2022-28568

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Attacker Value
Unknown

CVE-2022-24803

Disclosure Date: April 01, 2022 (last updated October 07, 2023)
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits.
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Attacker Value
Unknown

CVE-2021-27320

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Attacker Value
Unknown

CVE-2021-27319

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.