Show filters
104 Total Results
Displaying 71-80 of 104
Sort by:
Attacker Value
Unknown

CVE-2023-0732

Disclosure Date: February 07, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact leads to cross site scripting. The attack can be launched remotely. The identifier VDB-220369 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0686

Disclosure Date: February 06, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects the function update_cart of the file /oews/classes/Master.php?f=update_cart of the component HTTP POST Request Handler. The manipulation of the argument cart_id leads to sql injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The identifier VDB-220245 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0673

Disclosure Date: February 04, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file oews/?p=products/view_product.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The associated identifier of this vulnerability is VDB-220195.
Attacker Value
Unknown

CVE-2022-42109

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
Attacker Value
Unknown

CVE-2022-39977

Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.
Attacker Value
Unknown

CVE-2022-39978

Disclosure Date: October 27, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.
Attacker Value
Unknown

CVE-2022-41408

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
Attacker Value
Unknown

CVE-2022-41407

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
Attacker Value
Unknown

CVE-2022-41378

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=inventory/manage_inventory.
Attacker Value
Unknown

CVE-2022-41377

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=maintenance/manage_category.