CVE-2024-9034

CVSS v3 Score
7.3
High
CVSS v2 Score
7.5
High

Vulnerability Description

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS:7.3(High)

SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.

CWE-892015
CVSS:7.3(High)

SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.

CWE-892016
CVSS:7.3(High)

SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CWE-892016
CVSS:7.3(High)

A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSC...

CWE-892016
CVSS:7.3(High)

An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.

CWE-892017
CVSS:7.3(High)

connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.

CWE-892019