Tag
#sql
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.
Joomla DJ-Classifieds Ads extension version 3.9 suffers from a cross site scripting vulnerability.
jCart for OpenCart version 3.0.3.19 suffers from a cross site scripting vulnerability.
Joomla JoomRecipe extension version 4.2.2 suffers from a cross site scripting vulnerability.
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.
SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.