Pharmacy System
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42562 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | ||
| CVE-2022-34953 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. | ||
| CVE-2022-34952 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | ||
| CVE-2022-34951 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | ||
| CVE-2022-34949 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. | ||
| CVE-2022-34947 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. | ||
| CVE-2022-34946 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php. | ||
| CVE-2022-34945 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | ||
| CVE-2024-42561 | Hig | 0.58 | 8.8 | 0.09 | Aug 20, 2024 | Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php. | ||
| CVE-2007-3433 | 0.03 | — | 0.01 | Jun 27, 2007 | SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action. |
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
- risk 0.58cvss 8.8epss 0.09
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.
- CVE-2007-3433Jun 27, 2007risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.