Show filters
96 Total Results
Displaying 61-70 of 96
Sort by:
Attacker Value
Unknown
CVE-2021-42663
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.
0
Attacker Value
Unknown
CVE-2021-42662
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
0
Attacker Value
Unknown
CVE-2020-21012
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
0
Attacker Value
Unknown
CVE-2020-25889
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
0
Attacker Value
Unknown
CVE-2020-29283
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
0
Attacker Value
Unknown
CVE-2020-25273
Disclosure Date: October 08, 2020 (last updated February 22, 2025)
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
0
Attacker Value
Unknown
CVE-2020-25272
Disclosure Date: October 08, 2020 (last updated February 22, 2025)
In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
0
Attacker Value
Unknown
CVE-2020-23984
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
0
Attacker Value
Unknown
CVE-2020-15536
Disclosure Date: July 05, 2020 (last updated February 21, 2025)
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
0
Attacker Value
Unknown
CVE-2019-15774
Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
0