Show filters
107 Total Results
Displaying 51-60 of 107
Sort by:
Attacker Value
Unknown

CVE-2023-36311

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2023-36310

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2023-36309

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.
Attacker Value
Unknown

CVE-2023-39776

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
Attacker Value
Unknown

CVE-2023-38830

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.
Attacker Value
Unknown

CVE-2023-36136

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.
Attacker Value
Unknown

CVE-2023-36141

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-36139

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Attacker Value
Unknown

CVE-2023-36138

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.
Attacker Value
Unknown

CVE-2023-36137

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.