CVE-2024-8343 – SourceCodester Sentiment Based Movie Rating System User Registration Users.php sql injection
https://notcve.org/view.php?id=CVE-2024-8343
A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. • https://github.com/gurudattch/CVEs/blob/main/Sourcecodester-SQLi-Sentiment-Based-Moive-Rating.md https://vuldb.com/?ctiid.276222 https://vuldb.com/?id.276222 https://vuldb.com/?submit.399711 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8342 – SourceCodester Petshop Management System add_client.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-8342
A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown processing of the file /controllers/add_client.php. The manipulation of the argument image_profile leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_client.php%20any%20file%20upload.md https://vuldb.com/?ctiid.276221 https://vuldb.com/?id.276221 https://vuldb.com/?submit.399662 https://www.sourcecodester.com • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-8341 – SourceCodester Petshop Management System add_user.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-8341
A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_user.php%20any%20file%20upload.md https://vuldb.com/?ctiid.276220 https://vuldb.com/?id.276220 https://vuldb.com/?submit.399661 https://www.sourcecodester.com • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-8340 – SourceCodester Electric Billing Management System Actions.php sql injection
https://notcve.org/view.php?id=CVE-2024-8340
A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Electric%20Billing%20Management%20System/Electric%20Billing%20Managemen%20SQL-inject%20System%20Action.php%20SQL-inject.md https://vuldb.com/?ctiid.276219 https://vuldb.com/?id.276219 https://vuldb.com/?submit.399548 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-8339 – SourceCodester Electric Billing Management System Connection Code ?page=tracks sql injection
https://notcve.org/view.php?id=CVE-2024-8339
A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?page=tracks of the component Connection Code Handler. The manipulation of the argument code leads to sql injection. • https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Electric%20Billing%20Management%20System/Electric%20Billing%20Managemen%20SQL-inject%20System%20tracks.php%20SQL-inject.md https://vuldb.com/?ctiid.276218 https://vuldb.com/?id.276218 https://vuldb.com/?submit.399540 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •