Show filters
203 Total Results
Displaying 71-80 of 203
Sort by:
Attacker Value
Unknown

CVE-2023-49677

Disclosure Date: December 21, 2023 (last updated December 30, 2023)
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-49272

Disclosure Date: December 20, 2023 (last updated February 02, 2024)
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Attacker Value
Unknown

CVE-2023-49271

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Attacker Value
Unknown

CVE-2023-49270

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
Attacker Value
Unknown

CVE-2023-5011

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-5010

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-5007

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-47236

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.
Attacker Value
Unknown

CVE-2023-48737

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital Grup TriPay Payment Gateway allows Stored XSS.This issue affects TriPay Payment Gateway: from n/a through 3.2.7.
Attacker Value
Unknown

CVE-2023-5658

Disclosure Date: November 07, 2023 (last updated November 15, 2023)
The WP MapIt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_mapit' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.