Online Diagnostic Lab Management System
by Online Diagnostic Lab Management System Project
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43135 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. | ||
| CVE-2022-43058 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity. | ||
| CVE-2022-42064 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell. | ||
| CVE-2022-37152 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client" | ||
| CVE-2022-43226 | Hig | 0.57 | 8.8 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. | ||
| CVE-2022-37151 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2022 | There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0. | ||
| CVE-2022-43163 | Hig | 0.47 | 7.2 | 0.01 | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php. | ||
| CVE-2022-43162 | Hig | 0.47 | 7.2 | 0.01 | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php. | ||
| CVE-2022-43052 | Hig | 0.47 | 7.2 | 0.01 | Nov 7, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete. | ||
| CVE-2022-43051 | Hig | 0.47 | 7.2 | 0.01 | Nov 7, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test. | ||
| CVE-2022-43063 | Hig | 0.47 | 7.2 | 0.01 | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client. | ||
| CVE-2022-43062 | Hig | 0.47 | 7.2 | 0.01 | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment. | ||
| CVE-2022-43068 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation. | ||
| CVE-2022-43066 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message. | ||
| CVE-2022-43227 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment. | ||
| CVE-2022-43127 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php. | ||
| CVE-2022-43126 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php. | ||
| CVE-2022-43125 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php. | ||
| CVE-2022-43124 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | ||
| CVE-2022-41534 | Hig | 0.47 | 7.2 | 0.01 | Oct 13, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"
- risk 0.57cvss 8.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
- risk 0.49cvss 7.5epss 0.01
There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Page 1 of 2