Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown

CVE-2024-33962

Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/index.php' parameter.
Attacker Value
Unknown

CVE-2024-33961

Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php' parameter.
Attacker Value
Unknown

CVE-2024-33959

Disclosure Date: August 06, 2024 (last updated August 09, 2024)
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter.
Attacker Value
Unknown

CVE-2022-1102

Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-1101

Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated remotely. The identifier VDB-195785 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-38323

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-28080

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
Attacker Value
Unknown

CVE-2018-18795

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
0
Attacker Value
Unknown

CVE-2018-18794

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
0
Attacker Value
Unknown

CVE-2018-18793

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
0