Vulnerabilities
Vulnerable Software
Remyandrade:  Security Vulnerabilities
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-02-01
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-02-01
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
CVSS Score
6.1
EPSS Score
0.006
Published
2024-01-29
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
CVSS Score
7.2
EPSS Score
0.075
Published
2024-01-29
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
CVSS Score
7.2
EPSS Score
0.028
Published
2024-01-29
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
CVSS Score
9.8
EPSS Score
0.094
Published
2024-01-29
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
CVSS Score
4.8
EPSS Score
0.009
Published
2024-01-29
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
CVSS Score
6.1
EPSS Score
0.007
Published
2024-01-29
A vulnerability was found in SourceCodester School Visitor Log e-Book 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file log-book.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248750 is the identifier assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.002
Published
2023-12-22
A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-12-13


Contact Us

Shodan ® - All rights reserved