CVE-2023-3988 – Cafe Billing System Order index.php sql injection
https://notcve.org/view.php?id=CVE-2023-3988
A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. • https://github.com/excuses0217/CveHub/blob/main/Cafe%20Billing%20System%20index.php%20has%20Sqlinjection.md https://vuldb.com/?ctiid.235609 https://vuldb.com/?id.235609 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2689 – SourceCodester Billing Management System GET Parameter editproduct.php sql injection
https://notcve.org/view.php?id=CVE-2023-2689
A vulnerability classified as critical was found in SourceCodester Billing Management System 1.0. This vulnerability affects unknown code of the file editproduct.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/niyuchunqiu/cve/blob/main/SQL.md https://vuldb.com/?ctiid.228970 https://vuldb.com/?id.228970 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2595 – SourceCodester Billing Management System POST Parameter ajax_service.php sql injection
https://notcve.org/view.php?id=CVE-2023-2595
A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Parameter Handler. The manipulation of the argument drop_services leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Yastar/bug_report/blob/main/SQLi-1.md https://vuldb.com/?ctiid.228397 https://vuldb.com/?id.228397 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-27241
https://notcve.org/view.php?id=CVE-2023-27241
SourceCodester Water Billing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the lastname text box under the Add Client module. • https://github.com/kaikai-11/WaterBilling-System https://github.com/kaikai-11/WaterBilling-System/blob/main/README.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43213
https://notcve.org/view.php?id=CVE-2022-43213
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. Se descubrió que Billing System Project v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro id en editorder.php. • https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43213%28sql%20in%20editorder.php%29.md https://www.sourcecodester.com/php/14831/billing-system-project-php-source-code-free-download.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •