Show filters
107 Total Results
Displaying 91-100 of 107
Sort by:
Attacker Value
Unknown
CVE-2021-27314
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
0
Attacker Value
Unknown
CVE-2021-27317
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
0
Attacker Value
Unknown
CVE-2021-27318
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.
0
Attacker Value
Unknown
CVE-2021-27124
Disclosure Date: February 18, 2021 (last updated February 22, 2025)
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
0
Attacker Value
Unknown
CVE-2020-35416
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2020-29283
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
0
Attacker Value
Unknown
CVE-2020-24313
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
0
Attacker Value
Unknown
CVE-2020-9372
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
0
Attacker Value
Unknown
CVE-2016-10916
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
0
Attacker Value
Unknown
CVE-2019-14791
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
0