Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown
CVE-2022-28568
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
0
Attacker Value
Unknown
CVE-2022-24803
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits.
0
Attacker Value
Unknown
CVE-2022-0483
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
0
Attacker Value
Unknown
CVE-2021-44159
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.
0
Attacker Value
Unknown
CVE-2021-42338
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.
0
Attacker Value
Unknown
CVE-2020-6931
Disclosure Date: November 03, 2021 (last updated November 29, 2024)
HP Print and Scan Doctor may potentially be vulnerable to local elevation of privilege.
0
Attacker Value
Unknown
CVE-2021-25791
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
0
Attacker Value
Unknown
CVE-2021-27320
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
0
Attacker Value
Unknown
CVE-2021-27319
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
0
Attacker Value
Unknown
CVE-2021-27315
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
0