Doctor Appointment System Project ≫ Doctor Appointment System
10 Schwachstellen gefunden.
CVE-2023-40945
- EPSS 0.18%
- Veröffentlicht 11.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:20
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
CVE-2023-39852
- EPSS 0.91%
- Veröffentlicht 15.08.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:59
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot b...
CVE-2021-27319
- EPSS 72.22%
- Veröffentlicht 24.03.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:57:47
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
CVE-2021-27320
- EPSS 76.25%
- Veröffentlicht 24.03.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:57:47
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
CVE-2021-27315
- EPSS 71.38%
- Veröffentlicht 24.03.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:47
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
CVE-2021-27316
- EPSS 71.38%
- Veröffentlicht 24.03.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:47
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
CVE-2021-27314
- EPSS 78.71%
- Veröffentlicht 05.03.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:46
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
CVE-2021-27317
- EPSS 0.21%
- Veröffentlicht 01.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:57:47
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
CVE-2021-27318
- EPSS 0.27%
- Veröffentlicht 01.03.2021 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:57:47
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.
CVE-2021-27124
- EPSS 22.29%
- Veröffentlicht 18.02.2021 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:57:22
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.