Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sqliii

#21516of 53,624
11.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-39849
5.8
2024-10-10
Code Projects · Code-Projects Blood Bank System · CVE-2024-9804
**Name of the Vulnerable Software and Affected Versions** code-projects Blood Bank System version 1.0 **Description** A critical issue was discovered, affecting the file `/admin/campsdetails.php`. The manipulation of the `hospital` argument leads to SQL injection. This issue can be exploited remotely. **Recommendations** For code-projects Blood Bank System version 1.0, consider restricting access to the `/admin/campsdetails.php` file until a fix is available. As a temporary workaround, avoid using the `hospital` argument in the affected file to minimize the risk of exploitation.
PT-2024-39850
5.4
2024-10-10
Code Projects · Code-Projects Blood Bank System · CVE-2024-9805
**Name of the Vulnerable Software and Affected Versions** code-projects Blood Bank System version 1.0 **Description** A problem was found in the processing of the file "/admin/campsdetails.php". The manipulation of the argument `hospital/address/city/contact` leads to cross-site scripting. The attack may be initiated remotely. **Recommendations** For code-projects Blood Bank System version 1.0, consider restricting access to the "/admin/campsdetails.php" file until a fix is available. As a temporary workaround, avoid using the `hospital` parameter in the affected endpoint to minimize the risk of exploitation.