CVE-2023-0281 – SourceCodester Online Flight Booking Management System judge_panel.php sql injection
https://notcve.org/view.php?id=CVE-2023-0281
A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. • https://github.com/qyhmsys/cve-list/blob/master/Online%20Flight%20Booking%20Management%20System%20judge_panel.md https://vuldb.com/?ctiid.218276 https://vuldb.com/?id.218276 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-0245 – SourceCodester Online Flight Booking Management System add_contestant.php sql injection
https://notcve.org/view.php?id=CVE-2023-0245
A vulnerability, which was classified as critical, has been found in SourceCodester Online Flight Booking Management System. This issue affects some unknown processing of the file add_contestant.php. The manipulation of the argument add_contestant leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/f4cky0u/Security-vulnerabilities/blob/main/Online%20Flight%20Booking%20Management%20System%20add_contestant.php%20has%20SQLinject.md https://vuldb.com/?ctiid.218153 https://vuldb.com/?id.218153 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-4250 – Movie Ticket Booking System booking.php cross site scripting
https://notcve.org/view.php?id=CVE-2022-4250
A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerability is an unknown functionality of the file booking.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/aman05382/movie_ticket_booking_system_php/issues/2 https://vuldb.com/?id.214627 • CWE-707: Improper Neutralization •
CVE-2022-4247 – Movie Ticket Booking System booking.php sql injection
https://notcve.org/view.php?id=CVE-2022-4247
A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code of the file booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/aman05382/movie_ticket_booking_system_php/issues/1 https://vuldb.com/?id.214624 • CWE-707: Improper Neutralization •
CVE-2022-4249 – Movie Ticket Booking System POST Request cross site scripting
https://notcve.org/view.php?id=CVE-2022-4249
A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown function of the component POST Request Handler. The manipulation of the argument ORDER_ID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/aman05382/movie_ticket_booking_system_php/issues/5 https://vuldb.com/?id.214626 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-707: Improper Neutralization •