vighneshnair7

4 exploits Active since Oct 2024
CVE-2024-48427 NOMISEC HIGH WRITEUP
Sourcecodester Packers and Movers Management System 1.0 - Authenticated SQL Injection via id Parameter
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
1 stars
CVSS 8.8
CVE-2024-51030 NOMISEC MEDIUM WRITEUP
Sourcecodester Cab Management System 1.0 - SQL Injection via id Parameter
A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.
CVSS 6.5
CVE-2024-51031 NOMISEC MEDIUM WRITEUP
Sourcecodester Cab Management System 1.0 - Authenticated Stored Cross-Site Scripting via User Name Fields
A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.
CVSS 5.4
CVE-2024-48427 WRITEUP HIGH WRITEUP
Sourcecodester Packers and Movers Management System 1.0 - Authenticated SQL Injection via id Parameter
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
CVSS 8.8