CVE-2023-2595 – SourceCodester Billing Management System POST Parameter ajax_service.php sql injection
https://notcve.org/view.php?id=CVE-2023-2595
A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of the argument drop_services leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Yastar/bug_report/blob/main/SQLi-1.md https://vuldb.com/?ctiid.228397 https://vuldb.com/?id.228397 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-27241
https://notcve.org/view.php?id=CVE-2023-27241
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. • https://github.com/kaikai-11/WaterBilling-System https://github.com/kaikai-11/WaterBilling-System/blob/main/README.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43213
https://notcve.org/view.php?id=CVE-2022-43213
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. Se descubrió que Billing System Project v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro id en editorder.php. • https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43213%28sql%20in%20editorder.php%29.md https://www.sourcecodester.com/php/14831/billing-system-project-php-source-code-free-download.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43214
https://notcve.org/view.php?id=CVE-2022-43214
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. Se descubrió que Billing System Project v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro orderId en printOrder.php. • https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43214%28sql%20in%20printOrder.php%29.md https://www.sourcecodester.com/php/14831/billing-system-project-php-source-code-free-download.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-43215
https://notcve.org/view.php?id=CVE-2022-43215
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. Se descubrió que Billing System Project v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro endDate en getOrderReport.php. • https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43215%28sql%20in%20getOrderReport.php%29.md https://www.sourcecodester.com/php/14831/billing-system-project-php-source-code-free-download.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •