The 'bookisbn' parameter of the cart.php resource
does not validate the characters received and they
are sent unfiltered to the database.
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admindelete.php allows a remote attacker to delete any book.
SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to editbook.php, which could let a remote malicious user execute arbitrary code.
Arbitrary File Upload vulnerability in Online Book Store v1.0 in adminadd.php, which may lead to remote code execution.
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admindelete.php, which could let a remote malicious user execute arbitrary code.
Incorrect Access Control vulnerability in Online Book Store v1.0 via adminverify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to adminedit.php, which could let a remote malicious user execute arbitrary code.
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to editbook.php, which could let a remote malicious user execute arbitrary code.
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.