Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown
CVE-2024-33962
Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/index.php' parameter.
0
Attacker Value
Unknown
CVE-2024-33961
Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php' parameter.
0
Attacker Value
Unknown
CVE-2024-33959
Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter.
0
Attacker Value
Unknown
CVE-2022-1102
Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-1101
Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated remotely. The identifier VDB-195785 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-38323
Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-28080
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
0
Attacker Value
Unknown
CVE-2018-18795
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
0
Attacker Value
Unknown
CVE-2018-18794
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
0
Attacker Value
Unknown
CVE-2018-18793
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
0