Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2022-28568

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Attacker Value
Unknown

CVE-2022-24803

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits.
Attacker Value
Unknown

CVE-2022-0483

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
Attacker Value
Unknown

CVE-2021-44159

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.
0
Attacker Value
Unknown

CVE-2021-42338

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.
0
Attacker Value
Unknown

CVE-2020-6931

Disclosure Date: November 03, 2021 (last updated November 29, 2024)
HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Attacker Value
Unknown

CVE-2021-27320

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Attacker Value
Unknown

CVE-2021-27319

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
Attacker Value
Unknown

CVE-2021-27315

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.