Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-43739
Disclosure Date: September 28, 2023 (last updated October 08, 2023)
The 'bookisbn' parameter of the cart.php resource
does not validate the characters received and they
are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-27250
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
0
Attacker Value
Unknown
CVE-2021-34249
Disclosure Date: February 24, 2023 (last updated October 08, 2023)
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
0
Attacker Value
Unknown
CVE-2022-2771
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. Affected by this vulnerability is an unknown functionality of the file /obs/bookPerPub.php. The manipulation of the argument bookisbn leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-206167.
0
Attacker Value
Unknown
CVE-2022-2770
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System. Affected is an unknown function of the file /obs/book.php. The manipulation of the argument bookisbn leads to sql injection. It is possible to launch the attack remotely. VDB-206166 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2748
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple Online Book Store System. It has been classified as problematic. Affected is an unknown function of the file /admin/edit.php. The manipulation of the argument eid leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-206016.
0
Attacker Value
Unknown
CVE-2022-2747
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple Online Book Store and classified as critical. This issue affects some unknown processing of the file book.php. The manipulation of the argument book_isbn leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-206015.
0
Attacker Value
Unknown
CVE-2022-2746
Disclosure Date: August 11, 2022 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2020-23763
Disclosure Date: April 09, 2021 (last updated February 22, 2025)
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
0
Attacker Value
Unknown
CVE-2020-36003
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
0