Vulnerabilities > Doditsolutions

DATE CVE VULNERABILITY TITLE RISK
2017-12-21 CVE-2017-17830 Cross-Site Request Forgery (CSRF) vulnerability in Doditsolutions BUS Booking Script
Bus Booking Script has CSRF via admin/new_master.php.
network
low complexity
doditsolutions CWE-352
6.8
2017-12-21 CVE-2017-17829 SQL Injection vulnerability in Doditsolutions BUS Booking Script
Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter.
network
low complexity
doditsolutions CWE-89
7.2
2017-12-21 CVE-2017-17828 Cross-site Scripting vulnerability in Doditsolutions Busbooking-Script
Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.
network
low complexity
doditsolutions CWE-79
4.8