Show filters
107 Total Results
Displaying 81-90 of 107
Sort by:
Attacker Value
Unknown
CVE-2022-28568
Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
0
Attacker Value
Unknown
CVE-2021-41660
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
0
Attacker Value
Unknown
CVE-2021-24712
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
0
Attacker Value
Unknown
CVE-2021-24673
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-24614
Disclosure Date: September 13, 2021 (last updated November 28, 2024)
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-25791
Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
0
Attacker Value
Unknown
CVE-2021-27320
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
0
Attacker Value
Unknown
CVE-2021-27319
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
0
Attacker Value
Unknown
CVE-2021-27315
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
0
Attacker Value
Unknown
CVE-2021-27316
Disclosure Date: March 24, 2021 (last updated February 22, 2025)
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
0