CVE-2024-10410 – SourceCodester Online Hotel Reservation System controller.php upload unrestricted upload
https://notcve.org/view.php?id=CVE-2024-10410
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. • https://github.com/K1nako0/CVE-2024-10410 https://github.com/K1nako0/tmp_vuln9/blob/main/README.md https://vuldb.com/?ctiid.281953 https://vuldb.com/?id.281953 https://vuldb.com/?submit.431502 https://www.sourcecodester.com • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-10407 – SourceCodester Petrol Pump Management Software edit_customer.php sql injection
https://notcve.org/view.php?id=CVE-2024-10407
A vulnerability, which was classified as critical, was found in SourceCodester Petrol Pump Management Software 1.0. This affects an unknown part of the file /admin/edit_customer.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/K1nako0/tmp_vuln8/blob/main/README.md https://vuldb.com/?ctiid.281937 https://vuldb.com/?id.281937 https://vuldb.com/?submit.431336 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-10406 – SourceCodester Petrol Pump Management Software edit_fuel.php sql injection
https://notcve.org/view.php?id=CVE-2024-10406
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_fuel.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/K1nako0/tmp_vuln7/blob/main/README.md https://vuldb.com/?ctiid.281936 https://vuldb.com/?id.281936 https://vuldb.com/?submit.431335 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-10380 – SourceCodester Petrol Pump Management Software ajax_product.php sql injection
https://notcve.org/view.php?id=CVE-2024-10380
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/K1nako0/tmp_vuln5/blob/main/README.md https://vuldb.com/?ctiid.281810 https://vuldb.com/?id.281810 https://vuldb.com/?submit.431174 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-10371 – SourceCodester Payroll Management System main login buffer overflow
https://notcve.org/view.php?id=CVE-2024-10371
A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used. Es wurde eine Schwachstelle in SourceCodester Payroll Management System 1.0 entdeckt. • https://github.com/CveSecLook/cve/issues/63 https://vuldb.com/?ctiid.281763 https://vuldb.com/?id.281763 https://vuldb.com/?submit.430175 https://www.sourcecodester.com • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •