Doctor Appointment System Project
Doctor Appointment System Project Doctor Appointment System: vulnerabilidades y CVE
Doctor Appointment System Project Doctor Appointment System tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40945 | Crítica (9.8) | 0.93% | — | 11 sept 2023 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. |
| CVE-2023-39852 | Crítica (9.8) | 1.0% | — | 15 ago 2023 | Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled… |
| CVE-2021-27320 | Alta (7.5) | 9.3% | — | 24 mar 2021 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter. |
| CVE-2021-27319 | Alta (7.5) | 7.8% | — | 24 mar 2021 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter. |
| CVE-2021-27316 | Alta (7.5) | 7.8% | — | 24 mar 2021 | Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter. |
| CVE-2021-27315 | Alta (7.5) | 7.8% | — | 24 mar 2021 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter. |
| CVE-2021-27314 | Crítica (9.8) | 12% | — | 5 mar 2021 | SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page. |
| CVE-2021-27318 | Media (6.1) | 1.5% | — | 1 mar 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter. |
| CVE-2021-27317 | Media (6.1) | 1.3% | — | 1 mar 2021 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. |
| CVE-2021-27124 | Media (6.5) | 5.8% | — | 18 feb 2021 | SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack. |