VendorsOnline Travel Agency System Projectonline_travel_agency_system1.0
Vulnerabilities

Online Travel Agency System Project Online Travel Agency System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-31941
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.
Published 2023-08-17 · Modified
7.2EPSS 0.015
CVE-2023-31946
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.
Published 2023-08-17 · Modified
7.2EPSS 0.015
CVE-2023-31938
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31939
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31940
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31943
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31944
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31945
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.
Published 2023-08-17 · Modified
7.2EPSS 0.013
CVE-2023-31942
Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php.
Published 2023-08-17 · Modified
4.8EPSS 0.006