| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28433 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=. | ||
| CVE-2022-28432 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2. | ||
| CVE-2022-28431 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&sid=2. | ||
| CVE-2022-28429 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=. | ||
| CVE-2022-28427 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=. | ||
| CVE-2022-28426 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid=. | ||
| CVE-2022-28425 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=display&value=1&roleid=. | ||
| CVE-2022-28424 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&find=. | ||
| CVE-2022-28423 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete. | ||
| CVE-2022-28422 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit. | ||
| CVE-2022-28421 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=. | ||
| CVE-2022-28420 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=. | ||
| CVE-2022-28417 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28416 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28415 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. | ||
| CVE-2022-28414 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member. | ||
| CVE-2022-28413 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment. | ||
| CVE-2022-28412 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package. | ||
| CVE-2022-28411 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. | ||
| CVE-2022-28410 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. | ||
| CVE-2022-28030 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate. | |
| CVE-2022-28029 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. | ||
| CVE-2022-28028 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. | ||
| CVE-2022-28026 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=. | ||
| CVE-2022-28025 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year. | ||
| CVE-2022-28024 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade. | |
| CVE-2022-28023 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier. | ||
| CVE-2022-28022 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item. | ||
| CVE-2022-28021 | Cri | 0.66 | 9.8 | 0.24 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | ||
| CVE-2022-28743 | Cri | 0.59 | 9.1 | 0.01 | Apr 21, 2022 | Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware… | ||
| CVE-2022-0272 | Cri | 0.57 | 9.8 | 0.01 | Apr 21, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0. | ||
| CVE-2021-41162 | Cri | 0.00 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.… | ||
| CVE-2021-41161 | Cri | 0.00 | 9.3 | 0.01 | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known… | ||
| CVE-2016-20014 | Cri | 0.57 | 9.8 | 0.01 | Apr 21, 2022 | In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure. | ||
| CVE-2022-29528 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. | ||
| CVE-2021-43481 | Cri | 0.67 | 9.8 | 0.06 | Apr 20, 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | ||
| CVE-2022-26133 | Cri | 0.69 | 9.8 | 0.71 | Apr 20, 2022 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute… | ||
| CVE-2022-24861 | Cri | 0.00 | 9.9 | 0.03 | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user… | ||
| CVE-2022-0540 | Cri | 0.71 | 9.8 | 0.88 | Apr 20, 2022 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0… | ||
| CVE-2022-24799 | Cri | 0.00 | 9.6 | 0.01 | Apr 20, 2022 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and… | ||
| CVE-2022-1039 | — | Cri | 0.62 | 9.6 | 0.01 | Apr 20, 2022 | The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted… | |
| CVE-2022-0567 | Cri | 0.59 | 9.1 | 0.01 | Apr 20, 2022 | A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This… | ||
| CVE-2022-24826 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.… | ||
| CVE-2022-27862 | Cri | 0.64 | 9.8 | 0.02 | Apr 19, 2022 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | ||
| CVE-2022-21445 | Cri | 0.81 | 9.8 | 0.62 | KEV | Apr 19, 2022 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| CVE-2022-21431 | Cri | 0.65 | 10.0 | 0.02 | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated… | ||
| CVE-2022-21420 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2022 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise… | ||
| CVE-2022-0992 | Cri | 0.64 | 9.8 | 0.03 | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA… | ||
| CVE-2022-27104 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2022 | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. | ||
| CVE-2022-27927 | — | Cri | 0.65 | 9.8 | 0.14 | Apr 19, 2022 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter. |
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&sid=2.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=display&value=1&roleid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&find=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member.
- risk 0.64cvss 9.8epss 0.01
Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.
- risk 0.64cvss 9.8epss 0.01
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.
- risk 0.66cvss 9.8epss 0.24
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.
- risk 0.59cvss 9.1epss 0.01
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitrary remote code via a malicious firmware…
- risk 0.57cvss 9.8epss 0.01
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
- risk 0.00cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade.…
- risk 0.00cvss 9.3epss 0.01
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known…
- risk 0.57cvss 9.8epss 0.01
In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
- risk 0.67cvss 9.8epss 0.06
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
- risk 0.69cvss 9.8epss 0.71
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute…
- risk 0.00cvss 9.9epss 0.03
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user…
- risk 0.71cvss 9.8epss 0.88
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0…
- risk 0.00cvss 9.6epss 0.01
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML code and thus also JavaScript. If a user receives and…
- risk 0.62cvss 9.6epss 0.01
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted…
- risk 0.59cvss 9.1epss 0.01
A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress network policy that bypasses existing ingress policies of other pods in a cluster, allowing network traffic to access pods that should not be reachable. This…
- risk 0.64cvss 9.8epss 0.02
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…
- risk 0.64cvss 9.8epss 0.02
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
- risk 0.81cvss 9.8epss 0.62
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network…
- risk 0.65cvss 10.0epss 0.02
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated…
- risk 0.64cvss 9.8epss 0.01
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise…
- risk 0.64cvss 9.8epss 0.03
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA…
- risk 0.64cvss 9.8epss 0.01
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
- risk 0.65cvss 9.8epss 0.14
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.