
nu11secur1ty/CVE-nu11secur1ty
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.2 HIGH | — | ||
Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents. | |||
| 6.5 MEDIUM | — | ||
AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism. | |||
| 6.1 MEDIUM | — | ||
Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context. | |||
| 9.8 CRITICAL | — | ||
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system. | |||
| — | — | ||
Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. | |||
| 8.2 HIGH | — | ||
Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information. | |||
| — | — | ||
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access. | |||
| 7.5 HIGH | — | ||
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter. | |||
| 7.5 HIGH | — | ||
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter. | |||
| 6.1 MEDIUM | — | ||
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |||
| 6.1 MEDIUM | — | ||
phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |||
| 9.8 CRITICAL | — | ||
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | |||
| 9.8 CRITICAL | — | ||
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | |||
| 8.8 HIGH | — | ||
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. | |||
| 8.8 HIGH | — | ||
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request. | |||
| 7.5 HIGH | — | ||
Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php. | |||
| 8.8 HIGH | — | ||
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | |||
| 9.8 CRITICAL | — | ||
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php. | |||
| 8.8 HIGH | — | ||
Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | |||
| 6.1 MEDIUM | — | ||
Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php. | |||
| 8.8 HIGH | — | ||
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | |||
| 7.5 HIGH | — | ||
Atropim 1.5.26 is vulnerable to Directory Traversal. | |||
| 9.8 CRITICAL | — | ||
In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload. | |||
| 8.8 HIGH | — | ||
An improper SameSite Attribute vulnerability in pimCore v10.5.15 allows attackers to execute arbitrary code. | |||
| 6.1 MEDIUM | — | ||
bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |||
| 6.1 MEDIUM | — | ||
Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php. | |||
| 7.5 HIGH | — | ||
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter. | |||
| 9.8 CRITICAL | — | ||
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file. | |||
| 6.1 MEDIUM | — | ||
SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView. | |||
| 9.8 CRITICAL | — | ||
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | |||
| 9.8 CRITICAL | — | ||
SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter. | |||
| — | — | ||
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | |||
| 7.5 HIGH | — | ||
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter. | |||
| 8.8 HIGH | — | ||
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter. | |||
| 7.5 HIGH | — | ||
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. | |||
| 6.1 MEDIUM | — | ||
glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response. | |||
| 6.1 MEDIUM | — | ||
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list. | |||
| 6.5 MEDIUM | — | ||
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. | |||
| 8.8 HIGH | — | ||
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file. | |||
| 5.4 MEDIUM | — | ||
Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js. | |||
| 5.4 MEDIUM | — | ||
Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters. | |||
| 9.8 CRITICAL | — | ||
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php. | |||
| 9.8 CRITICAL | — | ||
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |||
| 7.5 HIGH | — | ||
Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. | |||
| 8.8 HIGH | — | ||
Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter. | |||
| 9.8 CRITICAL | 10 HIGH | ||
Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |||
| 7.5 HIGH | 5 MEDIUM | ||
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | |||
| 9.6 CRITICAL | 4.3 MEDIUM | ||
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app. | |||
| 9.8 CRITICAL | 10 HIGH | ||
Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php. | |||
| 7.8 HIGH | 6.8 MEDIUM | ||
A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registration page. | |||
| 6.1 MEDIUM | 4.3 MEDIUM | ||
Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page. | |||
| 9.6 CRITICAL | 6.8 MEDIUM | ||
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app. | |||
| 9.8 CRITICAL | 10 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form. | |||
| 5.4 MEDIUM | 3.5 LOW | ||
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters. | |||
| 7.5 HIGH | 5 MEDIUM | ||
The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system. | |||
| 7.5 HIGH | 5 MEDIUM | ||
The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve sensitive information for all users of this system. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. | |||
| 9.8 CRITICAL | 10 HIGH | ||
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. | |||
| 7.5 HIGH | 7.8 HIGH | ||
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server. | |||
| 9.8 CRITICAL | 10 HIGH | ||
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system. | |||
| 7.2 HIGH | 6.5 MEDIUM | ||
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server. | |||
| 8.8 HIGH | 6.5 MEDIUM | ||
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads. | |||
| 8.1 HIGH | 6.8 MEDIUM | ||
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell. | |||