Show filters
135 Total Results
Displaying 31-40 of 135
Sort by:
Attacker Value
Unknown
CVE-2024-0346
Disclosure Date: January 09, 2024 (last updated January 17, 2024)
A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testemonial leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-250114 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0345
Disclosure Date: January 09, 2024 (last updated January 17, 2024)
A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of the component User Registration. The manipulation of the argument Full_Name/Last_Name/Address with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250113 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-51354
Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlugins Appointment & Event Booking Calendar Plugin – Webba Booking.This issue affects Appointment & Event Booking Calendar Plugin – Webba Booking: from n/a through 4.5.33.
0
Attacker Value
Unknown
CVE-2023-5209
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-45019
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45018
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45015
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45012
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-4691
Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
0
Attacker Value
Unknown
CVE-2023-36384
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
0