CVE-2021-42662 – Online Event Booking And Reservation System 1.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2021-42662
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more. Se presenta una vulnerabilidad de tipo Cross Site Scripting (XSS) almacenada en Sourcecodester Online Event Booking and Reservation System in PHP/MySQL por medio del parámetro Holiday reason. Un atacante puede aprovechar esta vulnerabilidad para ejecutar comandos javascript en nombre de los navegantes del servidor web, que puede conllevar al robo de cookies y más Online Event Booking and Reservation System version 1.0 suffers from a persistent cross site scripting vulnerability. • https://github.com/0xDeku/CVE-2021-42662 http://packetstormsecurity.com/files/164615/Online-Event-Booking-And-Reservation-System-1.0-Cross-Site-Scripting.html https://github.com/TheHackingRabbi/CVE-2021-42662 https://www.exploit-db.com/exploits/50450 https://www.sourcecodester.com/php/14241/online-event-booking-and-reservation-system-phpmysql.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24480 – Event Geek <= 2.5.2 - Stored Cross-site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24480
The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue El plugin Event Geek WordPress versiones hasta 2.5.2, no sanea ni escapa de su configuración "Use your own" antes de mostrarla en la página, conllevando a un problema de tipo Cross-Site Scripting almacenado autenticado (admin+) • https://wpscan.com/vulnerability/243d417a-6fb9-4e17-9e12-a8c605f9af8a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-18795 – School Event Management System 1.0 - SQL Injection
https://notcve.org/view.php?id=CVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. School Event Management System 1.0 tiene una inyección SQL mediante el parámetro id en student/index.php o event/index.php. School Event Management System version 1.0 suffers from a remote SQL injection vulnerability. • https://www.exploit-db.com/exploits/45722 http://packetstormsecurity.com/files/150014/School-Event-Management-System-1.0-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-18794 – School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
https://notcve.org/view.php?id=CVE-2018-18794
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. School Event Management System 1.0 permite Cross-Site Request Forgery (CSRF) mediante user/controller.php?action=edit. School Event Management System version 1.0 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/45724 http://packetstormsecurity.com/files/150007/School-Event-Management-System-1.0-Cross-Site-Request-Forgery.html • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-18793 – School Event Management System 1.0 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. School Event Management System 1.0 permite la subida de archivos arbitrarios mediante event/controller.php?action=photos. School Event Management System version 1.0 suffers from a remote shell upload vulnerability. • https://www.exploit-db.com/exploits/45723 http://packetstormsecurity.com/files/150006/School-Event-Management-System-1.0-Shell-Upload.html • CWE-434: Unrestricted Upload of File with Dangerous Type •