Show filters
107 Total Results
Displaying 81-90 of 107
Sort by:
Attacker Value
Unknown

CVE-2022-28568

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
Attacker Value
Unknown

CVE-2021-41660

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
Attacker Value
Unknown

CVE-2021-24712

Disclosure Date: October 11, 2021 (last updated November 28, 2024)
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
Attacker Value
Unknown

CVE-2021-24673

Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-24614

Disclosure Date: September 13, 2021 (last updated November 28, 2024)
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-25791

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Attacker Value
Unknown

CVE-2021-27320

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Attacker Value
Unknown

CVE-2021-27319

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
Attacker Value
Unknown

CVE-2021-27315

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Attacker Value
Unknown

CVE-2021-27316

Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.