
xiumulty/CVE
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 9.8 CRITICAL | — | ||
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php. | |||
| 9.8 CRITICAL | — | ||
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php. | |||
| 9.8 CRITICAL | — | ||
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter. | |||
| 9.8 CRITICAL | — | ||
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | |||
| 9.8 CRITICAL | — | ||
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | |||
| 6.1 MEDIUM | — | ||
A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter. | |||
| 9.8 CRITICAL | — | ||
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php. | |||
| 9.8 CRITICAL | — | ||
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | |||
| 9.8 CRITICAL | — | ||
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | |||
| 9.8 CRITICAL | — | ||
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | |||
| 9.8 CRITICAL | — | ||
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. | |||
| 9.8 CRITICAL | — | ||
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | |||
| 6.1 MEDIUM | — | ||
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php. | |||
| 6.1 MEDIUM | — | ||
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php. | |||
| 9.8 CRITICAL | — | ||
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | |||
| 6.1 MEDIUM | — | ||
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php. | |||
| 6.1 MEDIUM | — | ||
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php. | |||
| 6.1 MEDIUM | — | ||
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php. | |||
| 9.8 CRITICAL | — | ||
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. | |||
| 9.8 CRITICAL | — | ||
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | |||
| 9.8 CRITICAL | — | ||
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | |||