Show filters
135 Total Results
Displaying 81-90 of 135
Sort by:
Attacker Value
Unknown

CVE-2022-29992

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.
Attacker Value
Unknown

CVE-2022-29990

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=.
Attacker Value
Unknown

CVE-2022-29989

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.
Attacker Value
Unknown

CVE-2022-29988

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
Attacker Value
Unknown

CVE-2022-29987

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-29986

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.
Attacker Value
Unknown

CVE-2022-29985

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
Attacker Value
Unknown

CVE-2022-29317

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
Attacker Value
Unknown

CVE-2022-1463

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Attacker Value
Unknown

CVE-2022-28094

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.