Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-43739 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-27250 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2021-34249 | SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application UR SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL. NVD description · AI analysis pending | 7.5 | 1% | PoC ×2 |
| — | |
| CVE-2020-23763 | SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-36003 | The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases. The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases. NVD description · AI analysis pending | 7.5 | 2% | PoC |
| — | |
| CVE-2020-24115 | In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — |