Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Online_diagnostic_lab_management_system
(Online_diagnostic_lab_management_system_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 30 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-10-13 | CVE-2022-41533 | Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-10-13 | CVE-2022-41534 | Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-10-14 | CVE-2022-42064 | Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell. | Online_diagnostic_lab_management_system | 9.8 | ||
2022-11-01 | CVE-2022-43124 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-01 | CVE-2022-43125 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-01 | CVE-2022-43126 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-01 | CVE-2022-43127 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-03 | CVE-2022-43062 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-03 | CVE-2022-43063 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client. | Online_diagnostic_lab_management_system | 7.2 | ||
2022-11-03 | CVE-2022-43062 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment. | Online_diagnostic_lab_management_system | 7.2 |