Show filters
257 Total Results
Displaying 31-40 of 257
Sort by:
Attacker Value
Unknown

CVE-2024-24041

Disclosure Date: February 01, 2024 (last updated February 08, 2024)
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
Attacker Value
Unknown

CVE-2024-22922

Disclosure Date: January 25, 2024 (last updated January 30, 2024)
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
Attacker Value
Unknown

CVE-2023-43144

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
Attacker Value
Unknown

CVE-2023-42359

Disclosure Date: September 18, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
Attacker Value
Unknown

CVE-2023-38916

Disclosure Date: August 15, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the user input fields.
Attacker Value
Unknown

CVE-2023-3970

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235569 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-3969

Disclosure Date: July 27, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235568.
Attacker Value
Unknown

CVE-2023-3806

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235074 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2016-15031

Disclosure Date: May 06, 2023 (last updated October 20, 2023)
A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is identified as 0083ec652786ddbb81335ea20da590df40035679. It is recommended to upgrade the affected component. VDB-228022 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2020-23327

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.