projectworlds kayıtları
projectworlds üreticisine ait 224 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 13
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')91
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')82
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
- CWE-284 Improper Access Control8
- CWE-434 Unrestricted Upload of File with Dangerous Type7
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
224 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-23833İstismar yok | Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary projectworlds · house rental · CWE-89 | Kritik9,8 | — | %4,2 | 15 Eyl 2020 |
40Planlayın | CVE-2020-24203İstismar yok | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management projectworlds · travel management system · CWE-425 | Kritik9,8 | — | %3,7 | 27 Ağu 2020 |
40Planlayın | CVE-2020-24199İstismar yok | Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct projectworlds · car rental project · CWE-434 | Kritik9,8 | — | %3,7 | 9 Eyl 2020 |
40Planlayın | CVE-2020-19113İstismar yok | Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.projectworlds · online book store project in php · CWE-434 | Kritik9,8 | — | %3,0 | 6 May 2021 |
40Planlayın | CVE-2020-24202İstismar yok | File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which alloprojectworlds · house rental and property listing project · CWE-434 | Kritik9,8 | — | %2,9 | 27 Ağu 2020 |
40Planlayın | CVE-2020-19114İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user projectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,9 | 6 May 2021 |
40Planlayın | CVE-2020-19107İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execuprojectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,9 | 6 May 2021 |
40Planlayın | CVE-2020-19108İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user exeprojectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,9 | 6 May 2021 |
40Planlayın | CVE-2020-19109İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user projectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,9 | 6 May 2021 |
40Planlayın | CVE-2020-19112İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious useprojectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,9 | 6 May 2021 |
40Planlayın | CVE-2020-19111İstismar yok | Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass autheprojectworlds · online book store project in php · CWE-287 | Kritik9,8 | — | %1,9 | 6 May 2021 |
39İzleyin | CVE-2020-11545İstismar yok | Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (accprojectworlds · official car rental system · CWE-89 | Kritik9,8 | — | %1,6 | 6 Nis 2020 |
39İzleyin | CVE-2020-19110İstismar yok | SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious uprojectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,6 | 6 May 2021 |
39İzleyin | CVE-2021-46307İstismar yok | An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.projectworlds · online examination system · CWE-89 | Kritik9,8 | — | %1,6 | 21 Oca 2022 |
39İzleyin | CVE-2021-43629İstismar yok | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.projectworlds · hospital management system in php · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2021 |
39İzleyin | CVE-2021-43631İstismar yok | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.projectworlds · hospital management system in php · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2021 |
39İzleyin | CVE-2021-43157İstismar yok | Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.projectworlds · online shopping system · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2021 |
39İzleyin | CVE-2021-43628İstismar yok | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.projectworlds · hospital management system in php · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2021 |
39İzleyin | CVE-2023-43144Kavram kanıtı | Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.projectworlds · asset management system project in php · CWE-89 | Kritik9,8 | — | %1,1 | 22 Eyl 2023 |
39İzleyin | CVE-2021-43155İstismar yok | Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.projectworlds · online book store project in php · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2021 |
39İzleyin | CVE-2023-5004İstismar yok | Hospital-management-system-in-php 378c157 - Blind SQL Injectionprojectworlds · hospital management system in php · CWE-89 | Kritik9,8 | — | %1,1 | 28 Eyl 2023 |
39İzleyin | CVE-2023-5053İstismar yok | SQL Injection in hospital-management-system-in-php 378c157 in index.phpprojectworlds · hospital management system in php · CWE-89 | Kritik9,8 | — | %1,1 | 28 Eyl 2023 |
39İzleyin | CVE-2021-46024İstismar yok | Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No logiprojectworlds · online-shopping-webvsite-in-php · CWE-89 | Kritik9,8 | — | %1,0 | 23 Oca 2022 |
39İzleyin | CVE-2023-44163İstismar yok | Online Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)projectworlds · online movie ticket booking system · CWE-89 | Kritik9,8 | — | %1,0 | 28 Eyl 2023 |
39İzleyin | CVE-2023-44164İstismar yok | Online Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)projectworlds · online movie ticket booking system · CWE-89 | Kritik9,8 | — | %1,0 | 28 Eyl 2023 |
- CVE-2020-2383340Planlayın
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary
KritikCVSS 9,8İstismar yokEPSS %4projectworlds · house rental15 Eyl 2020
- CVE-2020-2420340Planlayın
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management
KritikCVSS 9,8İstismar yokEPSS %4projectworlds · travel management system27 Ağu 2020
- CVE-2020-2419940Planlayın
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct
KritikCVSS 9,8İstismar yokEPSS %4projectworlds · car rental project9 Eyl 2020
- CVE-2020-1911340Planlayın
Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3projectworlds · online book store project in php6 May 2021
- CVE-2020-2420240Planlayın
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allo
KritikCVSS 9,8İstismar yokEPSS %3projectworlds · house rental and property listing project27 Ağu 2020
- CVE-2020-1911440Planlayın
SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1910740Planlayın
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execu
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1910840Planlayın
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user exe
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1910940Planlayın
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1911240Planlayın
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious use
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1911140Planlayın
Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authe
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2020-1154539İzleyin
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (acc
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · official car rental system6 Nis 2020
- CVE-2020-1911039İzleyin
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious u
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online book store project in php6 May 2021
- CVE-2021-4630739İzleyin
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
KritikCVSS 9,8İstismar yokEPSS %2projectworlds · online examination system21 Oca 2022
- CVE-2021-4362939İzleyin
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · hospital management system in php22 Ara 2021
- CVE-2021-4363139İzleyin
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · hospital management system in php22 Ara 2021
- CVE-2021-4315739İzleyin
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · online shopping system22 Ara 2021
- CVE-2021-4362839İzleyin
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · hospital management system in php22 Ara 2021
- CVE-2023-4314439İzleyin
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
KritikCVSS 9,8Kavram kanıtıEPSS %1projectworlds · asset management system project in php22 Eyl 2023
- CVE-2021-4315539İzleyin
Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · online book store project in php22 Ara 2021
- CVE-2023-500439İzleyin
Hospital-management-system-in-php 378c157 - Blind SQL Injection
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · hospital management system in php28 Eyl 2023
- CVE-2023-505339İzleyin
SQL Injection in hospital-management-system-in-php 378c157 in index.php
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · hospital management system in php28 Eyl 2023
- CVE-2021-4602439İzleyin
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No logi
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · online-shopping-webvsite-in-php23 Oca 2022
- CVE-2023-4416339İzleyin
Online Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · online movie ticket booking system28 Eyl 2023
- CVE-2023-4416439İzleyin
Online Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
KritikCVSS 9,8İstismar yokEPSS %1projectworlds · online movie ticket booking system28 Eyl 2023