Show filters
104 Total Results
Displaying 91-100 of 104
Sort by:
Attacker Value
Unknown
CVE-2020-29284
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
0
Attacker Value
Unknown
CVE-2020-28994
Disclosure Date: November 24, 2020 (last updated February 22, 2025)
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
0
Attacker Value
Unknown
CVE-2019-18416
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
0
Attacker Value
Unknown
CVE-2019-18417
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
0
Attacker Value
Unknown
CVE-2019-18414
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-18415
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
0
Attacker Value
Unknown
CVE-2019-15842
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-15819
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
0
Attacker Value
Unknown
CVE-2017-17614
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Food Order Script 1.0 has SQL Injection via the /list city parameter.
0
Attacker Value
Unknown
CVE-2015-0904
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.
0