Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Very High
CVE-2021-41649
Disclosure Date: October 01, 2021 (last updated November 28, 2024)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
3
Attacker Value
Very High
CVE-2021-41648
Disclosure Date: October 01, 2021 (last updated November 28, 2024)
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
2
Attacker Value
Unknown
CVE-2023-3337
Disclosure Date: June 20, 2023 (last updated October 08, 2023)
A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched remotely. The identifier VDB-232009 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3311
Disclosure Date: June 18, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231807.
0
Attacker Value
Unknown
CVE-2022-42109
Disclosure Date: November 29, 2022 (last updated October 08, 2023)
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
0