Author: Angelo Barbosa

CVE-2024-9041 | SourceCodester Best House Rental Management System 1.0 ajax.php firstname/lastname/email sql injection

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=update_account. The manipulation of the argument firstname/lastname/email leads to sql injection. This vulnerability was named CVE-2024-9041. The attack can be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2024-9040 | code-projects Blood Bank Management System 1.0 Password cleartext storage in a file or on disk

A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. This vulnerability is uniquely identified as CVE-2024-9040. An attack has to be approached locally. Furthermore, there is an exploit...

Read More

CVE-2024-9039 | SourceCodester Best House Rental Management System 1.0 /ajax.php firstname/lastname/email sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=signup. The manipulation of the argument firstname/lastname/email leads to sql injection. This vulnerability is handled as CVE-2024-9039. The attack may be launched remotely. Furthermore, there is an exploit...

Read More

CVE-2024-9038 | Codezips Online Shopping Portal 1.0 insert-product.php productimage1/productimage2/productimage3 unrestricted upload

A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. This vulnerability is known as CVE-2024-9038. The attack can be launched remotely. Furthermore, there is an exploit...

Read More