Show filters
205 Total Results
Displaying 51-60 of 205
Sort by:
Attacker Value
Unknown

CVE-2023-3227

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
Attacker Value
Unknown

CVE-2023-2689

Disclosure Date: May 14, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in SourceCodester Billing Management System 1.0. This vulnerability affects unknown code of the file editproduct.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-228970 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-2595

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of the argument drop_services leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228397 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2020-23647

Disclosure Date: April 28, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
Attacker Value
Unknown

CVE-2023-27241

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module.
Attacker Value
Unknown

CVE-2023-21824

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
Attacker Value
Unknown

CVE-2022-43213

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
Attacker Value
Unknown

CVE-2022-43212

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
Attacker Value
Unknown

CVE-2022-43214

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
Attacker Value
Unknown

CVE-2022-43215

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.