Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

Datalife Engine 10 SQL Injection

Datalife Engine version 10 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
Cyber Infinite CMS 1.0 SQL Injection

Cyber Infinite CMS version 1.0 suffers from a remote SQL injection vulnerability.

CSC-CMS 1.0.0 SQL Injection

CSC-CMS version 1.0.0 suffers from a remote SQL injection vulnerability.

CMS Genetics Centre 4.0.1 SQL Injection

CMS Genetics Centre version 4.0.1 suffers from a remote SQL injection vulnerability.

Conference Management Software 3.5.1 SQL Injection

Conference Management Software version 3.5.1 suffers from a remote SQL injection vulnerability.

CVE-2023-2843

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVE-2023-4193

A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_fee.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-236236.

CVE-2023-4192

A vulnerability, which was classified as critical, was found in SourceCodester Resort Reservation System 1.0. This affects an unknown part of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236235.

CVE-2023-4185

A vulnerability was found in SourceCodester Online Hospital Management System 1.0. It has been classified as critical. Affected is an unknown function of the file patientlogin.php. The manipulation of the argument loginid/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-236220.