Show filters
112 Total Results
Displaying 91-100 of 112
Sort by:
Attacker Value
Unknown

CVE-2022-29989

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.
Attacker Value
Unknown

CVE-2022-29988

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
Attacker Value
Unknown

CVE-2022-29987

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-29986

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.
Attacker Value
Unknown

CVE-2022-29985

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
Attacker Value
Unknown

CVE-2022-28094

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
Attacker Value
Unknown

CVE-2022-28093

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-28115

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
Attacker Value
Unknown

CVE-2021-44866

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2021-42663

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.