Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2022-30794: bug_report/SQLi-1.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.

CVE
#sql#vulnerability#windows#php#firefox
CVE-2022-30799: bug_report/SQLi-5.md at main · k0xx11/bug_report

Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.

CVE-2022-29627: OpenSource/exploit_idor.md at main · nsparker1337/OpenSource

An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.

CVE-2022-29628: OpenSource/exploit_rxss.md at main · nsparker1337/OpenSource

A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.

CVE-2022-29659: Responsive Online Blog Website using PHP/MySQL with Source Code

Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

CVE-2022-30352: SQL injection in phpABook

phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.

CVE-2022-30817: bug_report/SQLi-1.md at main · k0xx11/bug_report

Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.

CVE-2022-30814: bug_report/SQLi-5.md at main · k0xx11/bug_report

elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.