← Back

Online Movie Ticket Booking System

online_movie_ticket_booking_system

Vendor: Projectworlds • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Sep 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Sep 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Sep 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.
1Projectworlds
1Online Movie Ticket Booking System
Nov 21, 2024
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive informati...Show more
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.Show less