Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-1504 | A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND 'PhRa'='PhRa leads to sql injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223408. NVD description · AI analysis pending | 8.1 | <1% | PoC ×2 |
| — | |
| CVE-2023-26905 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-2682 | A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205670 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — |