CVE-2021-42667
https://notcve.org/view.php?id=CVE-2021-42667
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server. Se presenta una vulnerabilidad de inyección SQL en Sourcecodester Online Event Booking and Reservation System en PHP en event-management/views. Un atacante puede aprovechar esta vulnerabilidad para manipular una consulta sql llevada a cabo. • https://github.com/0xDeku/CVE-2021-42667 https://github.com/TheHackingRabbi/CVE-2021-42667 https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-42667 https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-42663
https://notcve.org/view.php?id=CVE-2021-42663
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice. Se presenta una vulnerabilidad de inyección de HTML en Sourcecodester Online Event Booking and Reservation System en PHP/MySQL por medio del parámetro msg en el archivo /event-management/index.php. Un atacante puede aprovechar esta vulnerabilidad para cambiar la visibilidad del sitio web. • https://github.com/0xDeku/CVE-2021-42663 https://github.com/TheHackingRabbi/CVE-2021-42663 https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-42662 – Online Event Booking And Reservation System 1.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2021-42662
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more. Se presenta una vulnerabilidad de tipo Cross Site Scripting (XSS) almacenada en Sourcecodester Online Event Booking and Reservation System in PHP/MySQL por medio del parámetro Holiday reason. Un atacante puede aprovechar esta vulnerabilidad para ejecutar comandos javascript en nombre de los navegantes del servidor web, que puede conllevar al robo de cookies y más Online Event Booking and Reservation System version 1.0 suffers from a persistent cross site scripting vulnerability. • https://github.com/0xDeku/CVE-2021-42662 http://packetstormsecurity.com/files/164615/Online-Event-Booking-And-Reservation-System-1.0-Cross-Site-Scripting.html https://github.com/TheHackingRabbi/CVE-2021-42662 https://www.exploit-db.com/exploits/50450 https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-21012
https://notcve.org/view.php?id=CVE-2020-21012
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. Sourcecodester Hotel and Lodge Management System versión 2.0, es vulnerable a una inyección SQL no autenticada y puede permitir a atacantes remotos ejecutar comandos SQL arbitrarios por medio del parámetro email en la página de edición de Customer, Room, Currency, Room Booking Details, o Tax Details • https://github.com/hitIer/web_test/tree/master/hotel • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-25889 – Online Bus Booking System Project Using PHP MySQL 1.0 SQL Injection
https://notcve.org/view.php?id=CVE-2020-25889
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege. Una vulnerabilidad de inyección SQL en Online Bus Booking System Project Using PHP/MySQL versión 1.0, permite a atacantes remotos omitir la autenticación y ejecutar comandos SQL arbitrarios Online Bus Booking System Project using PHP MySQL version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. • http://packetstormsecurity.com/files/160397/Online-Bus-Booking-System-Project-Using-PHP-MySQL-1.0-SQL-Injection.html http://seclists.org/fulldisclosure/2020/Dec/4 https://seclists.org/fulldisclosure/2020/Dec/4 https://www.sourcecodester.com/php/14438/online-bus-booking-system-project-using-phpmysql.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •