Filtered by vendor Itsourcecode Subscriptions
Total 76 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-37872 1 Itsourcecode 1 Billing System 2024-11-21 8.1 High
SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2024-37871 1 Itsourcecode 1 Online Discussion Forum 2024-11-21 8.2 High
SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter.
CVE-2024-37870 1 Itsourcecode 1 Learning Management System Project In Php 2024-11-21 9.8 Critical
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.
CVE-2024-37849 1 Itsourcecode 1 Billing System 2024-11-21 9.8 Critical
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.
CVE-2024-37840 1 Itsourcecode 1 Learning Management System Project In Php 2024-11-21 8.8 High
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
CVE-2024-37831 1 Itsourcecode 1 Payroll Management System 2024-11-21 9.1 Critical
Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.
CVE-2024-50972 2 Angeljudesuarez, Itsourcecode 2 Construction Management System, Construction Management System 2024-11-18 6.5 Medium
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
CVE-2024-50971 2 Angeljudesuarez, Itsourcecode 2 Construction Management System, Construction Management System 2024-11-18 6.5 Medium
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
CVE-2024-50970 2 Itsourcecode, Nikoarroyocuraza 2 Online Furniture Shopping Project, Online Furniture Shopping Project 2024-11-18 6.5 Medium
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2024-10738 2 Angeljudesuarez, Itsourcecode 2 Farm Management System, Farm Management System 2024-11-05 6.3 Medium
A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. The manipulation of the argument breed leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10759 2 Angeljudesuarez, Itsourcecode 2 Farm Management System, Farm Management System 2024-11-05 6.3 Medium
A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The manipulation of the argument pigno/weight/arrived/breed/remark/status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "pigno" to be affected. But it must be assumed that other parameters are affected as well.
CVE-2024-48657 2 Itsourcecode, Princelycesar 2 Hospital Management System, Hospital Management System 2024-10-24 8.1 High
SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-48656 2 Angeljudesuarez, Itsourcecode 2 Student Management System, Student Management System 2024-10-24 5.4 Medium
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-46300 2 Angeljudesuarez, Itsourcecode 2 Placement Management System, Placement Management System 2024-10-10 6.1 Medium
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVE-2024-9036 1 Itsourcecode 1 Online Book Store 2024-09-26 6.3 Medium
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-8611 2 Angeljudesuarez, Itsourcecode 2 Tailoring Management System, Tailoring Management System 2024-09-18 6.3 Medium
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7500 2 Angeljudesuarez, Itsourcecode 2 Airline Reservation System, Airline Reservation System 2024-09-11 6.3 Medium
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273626 is the identifier assigned to this vulnerability.
CVE-2024-7506 2 Angeljudesuarez, Itsourcecode 2 Tailoring Management System, Tailoring Management System 2024-09-11 6.3 Medium
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The manipulation of the argument bgimg leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273649 was assigned to this vulnerability.
CVE-2024-7505 2 Itsourcecode, Rainniar 2 Bike Delivery System, Bike Delivery System 2024-09-11 7.3 High
A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.
CVE-2024-8570 2 Angeljudesuarez, Itsourcecode 2 Tailoring Management System, Tailoring Management System 2024-09-11 6.3 Medium
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.