CVE-2024-2332 – SourceCodester Online Mobile Management Store HTTP GET Request manage_category.php sql injection
https://notcve.org/view.php?id=CVE-2024-2332
A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php of the component HTTP GET Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. • https://github.com/vanitashtml/CVE-Dumps/blob/main/Blind%20SQL%20Injection%20Manage%20Category%20-%20Mobile%20Management%20Store.md https://vuldb.com/?ctiid.256283 https://vuldb.com/?id.256283 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-2331 – SourceCodester Tourist Reservation System System.cpp ad_writedata buffer overflow
https://notcve.org/view.php?id=CVE-2024-2331
A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file System.cpp. The manipulation of the argument ad_code leads to buffer overflow. The attack can be initiated remotely. • https://github.com/wkeyi0x1/vul-report/blob/main/Tourist%20Reservation%20System%20using%20C%2B%2B%20with%20Free%20Source%20Code/buffer-overflow-1.md https://vuldb.com/?ctiid.256282 https://vuldb.com/?id.256282 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2024-2168 – SourceCodester Online Tours & Travels Management System HTTP POST Request expense_category.php sql injection
https://notcve.org/view.php?id=CVE-2024-2168
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the argument status leads to sql injection. It is possible to launch the attack remotely. • https://github.com/W01fh4cker/CVE-2024-21683-RCE https://github.com/r00t7oo2jm/-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server https://github.com/absholi7ly/-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server https://github.com/xh4vm/CVE-2024-21683 https://github.com/phucrio/CVE-2024-21683-RCE https://vuldb.com/?ctiid.255678 https://vuldb.com/?id.255678 https://www.yuque.com/mailemonyeyongjuan/nekc0f/uoobn101h48xv6ih • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-2156 – SourceCodester Best POS Management System admin_class.php sql injection
https://notcve.org/view.php?id=CVE-2024-2156
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. Affected is an unknown function of the file admin_class.php. The manipulation of the argument img leads to sql injection. It is possible to launch the attack remotely. • https://github.com/wkeyi0x1/vul-report/blob/main/Best%20pos%20management%20system%20in%20php/Report-SQLI-1.md https://vuldb.com/?ctiid.255588 https://vuldb.com/?id.255588 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-2155 – SourceCodester Best POS Management System index.php file inclusion
https://notcve.org/view.php?id=CVE-2024-2155
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/wkeyi0x1/vul-report/blob/main/Best%20pos%20management%20system%20in%20php/report.md https://vuldb.com/?ctiid.255587 https://vuldb.com/?id.255587 • CWE-73: External Control of File Name or Path •