VYPR

Vendor CVEs

Janobe

All CVEs

196 total · sorted by risk
  • CVE-2021-3239CriFeb 15, 2021
    risk 0.65cvss 9.8epss 0.18

    E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.

  • CVE-2026-36236CriApr 10, 2026
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

  • CVE-2024-44812CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

  • CVE-2024-33974CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in…

  • CVE-2024-33973CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance'…

  • CVE-2024-33972CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in…

  • CVE-2024-33971CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in…

  • CVE-2024-33970CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in…

  • CVE-2024-33969CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33968CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and…

  • CVE-2024-33967CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33966CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in…

  • CVE-2024-33965CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33964CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33963CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33962CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in…

  • CVE-2024-33961CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in…

  • CVE-2024-33960CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in…

  • CVE-2024-33959CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in…

  • CVE-2024-33958CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.

  • CVE-2024-33957CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter

  • CVE-2023-43470CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

  • CVE-2023-43469CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

  • CVE-2023-43468CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

  • CVE-2023-27213CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

  • CVE-2022-46471CriJan 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter at /healthcare/Admin/consulting_detail.php.

  • CVE-2022-39976CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.

  • CVE-2022-31357CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.

  • CVE-2022-31356CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.

  • CVE-2022-31355CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.

  • CVE-2022-31338CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.

  • CVE-2022-31337CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.

  • CVE-2022-31336CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.

  • CVE-2022-31335CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.

  • CVE-2022-31329CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.

  • CVE-2022-31328CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.

  • CVE-2022-31327CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.

  • CVE-2022-28439CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.

  • CVE-2022-28438CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=.

  • CVE-2022-28437CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.

  • CVE-2022-28436CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.

  • CVE-2022-28435CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1.

  • CVE-2022-28434CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.

  • CVE-2022-28433CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.

  • CVE-2022-28432CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2.

  • CVE-2022-28431CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&sid=2.

  • CVE-2022-28429CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=.

  • CVE-2022-28427CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=.

  • CVE-2022-28426CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid=.

  • CVE-2022-28425CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=display&value=1&roleid=.

Page 1 of 4