xiumulty/CVE

xiumulty/CVE

Releases0
Stars3
For CVE submission and retention

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.

9.8 CRITICAL

Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.

9.8 CRITICAL

Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.

6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

9.8 CRITICAL

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.

6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.

9.8 CRITICAL

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

9.8 CRITICAL

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

9.8 CRITICAL

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

9.8 CRITICAL

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

9.8 CRITICAL

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

9.8 CRITICAL

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

9.8 CRITICAL

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

6.1 MEDIUM

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

6.1 MEDIUM

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.

9.8 CRITICAL

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

6.1 MEDIUM

Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.

6.1 MEDIUM

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

6.1 MEDIUM

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.

9.8 CRITICAL

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.

9.8 CRITICAL

Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.

9.8 CRITICAL

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.