Online Travel Agency System Project
Online Travel Agency System Project Online Travel Agency System: vulnerabilidades y CVE
Online Travel Agency System Project Online Travel Agency System tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-31946 | Alta (7.2) | 1.5% | — | 17 ago 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php. |
| CVE-2023-31945 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. |
| CVE-2023-31944 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. |
| CVE-2023-31943 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php. |
| CVE-2023-31942 | Media (4.8) | 0.64% | — | 17 ago 2023 | Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php. |
| CVE-2023-31941 | Alta (7.2) | 1.5% | — | 17 ago 2023 | File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php. |
| CVE-2023-31940 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php. |
| CVE-2023-31939 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php. |
| CVE-2023-31938 | Alta (7.2) | 1.3% | — | 17 ago 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php. |