Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2024-2075
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255391.
0
Attacker Value
Unknown
CVE-2024-24496
Disclosure Date: February 08, 2024 (last updated February 22, 2024)
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
0
Attacker Value
Unknown
CVE-2024-24495
Disclosure Date: February 08, 2024 (last updated February 22, 2024)
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
0
Attacker Value
Unknown
CVE-2024-24494
Disclosure Date: February 08, 2024 (last updated September 06, 2024)
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.
0
Attacker Value
Unknown
CVE-2024-24140
Disclosure Date: January 29, 2024 (last updated February 03, 2024)
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
0