Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2020-29168

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
Attacker Value
Unknown

CVE-2015-10050

Disclosure Date: January 15, 2023 (last updated October 20, 2023)
A vulnerability was found in brandonfire miRNA_Database_by_PHP_MySql. It has been declared as critical. This vulnerability affects the function __construct/select_single_rna/count_rna of the file inc/model.php. The manipulation leads to sql injection. The patch is identified as 307c5d510841e6142ddcbbdbb93d0e8a0dc3fd6a. It is recommended to apply a patch to fix this issue. VDB-218374 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-3779

Disclosure Date: June 28, 2022 (last updated October 07, 2023)
A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user. This issue was resolved in version 2.10.0 and later.
Attacker Value
Unknown

CVE-2022-28102

Disclosure Date: April 28, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
Attacker Value
Unknown

CVE-2020-29283

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
Attacker Value
Unknown

CVE-2020-28688

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2020-28687

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2019-14939

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.
0
Attacker Value
Unknown

CVE-2018-3754

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.
0
Attacker Value
Unknown

CVE-2018-10757

Disclosure Date: May 05, 2018 (last updated November 26, 2024)
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
0