Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown

CVE-2022-34947

Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
Attacker Value
Unknown

CVE-2022-34946

Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
Attacker Value
Unknown

CVE-2022-34945

Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
Attacker Value
Unknown

CVE-2022-30887

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
Attacker Value
Unknown

CVE-2022-30407

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
Attacker Value
Unknown

CVE-2018-18704

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
0
Attacker Value
Unknown

CVE-2007-3433

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
0
Attacker Value
Unknown

CVE-2007-3434

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
0