Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown

CVE-2021-46067

Disclosure Date: January 06, 2022 (last updated October 07, 2023)
In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
Attacker Value
Unknown

CVE-2021-46080

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.
Attacker Value
Unknown

CVE-2021-46076

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.
Attacker Value
Unknown

CVE-2021-41962

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.
Attacker Value
Unknown

CVE-2017-1000474

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.
0