Show filters
104 Total Results
Displaying 91-100 of 104
Sort by:
Attacker Value
Unknown

CVE-2020-19108

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2020-19111

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.
Attacker Value
Unknown

CVE-2020-19112

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2020-19110

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.
Attacker Value
Unknown

CVE-2020-19113

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
Attacker Value
Unknown

CVE-2020-27397

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.
Attacker Value
Unknown

CVE-2020-25761

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.
Attacker Value
Unknown

CVE-2020-25760

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2020-23833

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
Attacker Value
Unknown

CVE-2020-24199

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.