Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-09-29 CVE-2023-43909 SQL Injection vulnerability in Hospital Management System Project Hospital Management System
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
network
low complexity
hospital-management-system-project CWE-89
critical
9.1
2023-09-28 CVE-2023-43014 SQL Injection vulnerability in Projectworlds Asset Management System 1.0
Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
network
low complexity
projectworlds CWE-89
8.8
2023-09-28 CVE-2023-43739 SQL Injection vulnerability in Online Book Store Project Online Book Store Project 1.0
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
online-book-store-project-project CWE-89
critical
9.8
2023-09-28 CVE-2023-44163 SQL Injection vulnerability in Projectworlds Online Movie Ticket Booking System 1.0
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-09-28 CVE-2023-44164 SQL Injection vulnerability in Projectworlds Online Movie Ticket Booking System 1.0
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-09-28 CVE-2023-44166 SQL Injection vulnerability in Projectworlds Online Movie Ticket Booking System 1.0
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-09-28 CVE-2023-43013 SQL Injection vulnerability in Projectworlds Asset Management System 1.0
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-09-28 CVE-2023-5004 SQL Injection vulnerability in Projectworlds Hospital Management System in PHP 20180617
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
network
low complexity
projectworlds CWE-89
critical
9.8
2023-09-28 CVE-2023-30415 SQL Injection vulnerability in Oretnom23 Packers and Movers Management System 1.0
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
network
low complexity
oretnom23 CWE-89
critical
9.8
2023-09-28 CVE-2023-38870 SQL Injection vulnerability in Economizzer 0.9/April2023
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1.
network
low complexity
economizzer CWE-89
critical
9.8