Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-3988
Disclosure Date: July 28, 2023 (last updated February 25, 2025)
A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235609 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27241
Disclosure Date: March 27, 2023 (last updated February 24, 2025)
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module.
0
Attacker Value
Unknown
CVE-2022-43213
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
0
Attacker Value
Unknown
CVE-2022-43212
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
0
Attacker Value
Unknown
CVE-2022-43214
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
0
Attacker Value
Unknown
CVE-2022-43215
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
0
Attacker Value
Unknown
CVE-2022-41504
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-41498
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.
0
Attacker Value
Unknown
CVE-2022-41440
Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.
0
Attacker Value
Unknown
CVE-2022-41439
Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.
0