Show filters
104 Total Results
Displaying 61-70 of 104
Sort by:
Attacker Value
Unknown

CVE-2023-44267

Disclosure Date: October 26, 2023 (last updated November 04, 2023)
Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-44174

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2023-44166

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-44164

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-44163

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-43014

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
Attacker Value
Unknown

CVE-2023-5185

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Attacker Value
Unknown

CVE-2023-5053

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
Attacker Value
Unknown

CVE-2023-5004

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
Attacker Value
Unknown

CVE-2023-44173

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.