Show filters
104 Total Results
Displaying 71-80 of 104
Sort by:
Attacker Value
Unknown

CVE-2023-43740

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Attacker Value
Unknown

CVE-2023-43013

Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
Attacker Value
Unknown

CVE-2023-43144

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
Attacker Value
Unknown

CVE-2022-42066

Disclosure Date: October 14, 2022 (last updated October 08, 2023)
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
Attacker Value
Unknown

CVE-2021-45852

Disclosure Date: March 16, 2022 (last updated February 23, 2025)
An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.
Attacker Value
Unknown

CVE-2021-44866

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2021-46024

Disclosure Date: January 23, 2022 (last updated February 23, 2025)
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
Attacker Value
Unknown

CVE-2021-46307

Disclosure Date: January 21, 2022 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
Attacker Value
Unknown

CVE-2021-43631

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
Attacker Value
Unknown

CVE-2021-43630

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.