CVE-2021-38758

Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_catering_reservation_system_project:online_catering_reservation_system:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:18

Type Values Removed Values Added
References () https://attackerkb.com/topics/XuEb81tsid/online-catering-reservation-dt-food-catering-by-oretnom23-v1-0-sql-injection---login - Third Party Advisory () https://attackerkb.com/topics/XuEb81tsid/online-catering-reservation-dt-food-catering-by-oretnom23-v1-0-sql-injection---login - Third Party Advisory
References () https://github.com/dumpling-soup/Online-Catering-Reservation-DT/blob/main/README.md - Exploit, Third Party Advisory () https://github.com/dumpling-soup/Online-Catering-Reservation-DT/blob/main/README.md - Exploit, Third Party Advisory
References () https://github.com/nu11secur1ty/CVE-mitre/blob/main/CVE-2021-38758/README.MD - Broken Link () https://github.com/nu11secur1ty/CVE-mitre/blob/main/CVE-2021-38758/README.MD - Broken Link
References () https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38758 - Broken Link () https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38758 - Broken Link
References () https://github.com/nu11secur1ty/CVE-mitre/tree/main/Online-Catering-Reservation-DT-Food-Catering - Exploit, Third Party Advisory () https://github.com/nu11secur1ty/CVE-mitre/tree/main/Online-Catering-Reservation-DT-Food-Catering - Exploit, Third Party Advisory

21 Sep 2021, 19:20

Type Values Removed Values Added
CWE CWE-20
CPE cpe:2.3:a:online_catering_reservation_system_project:online_catering_reservation_system:-:*:*:*:*:*:*:* cpe:2.3:a:online_catering_reservation_system_project:online_catering_reservation_system:1.0:*:*:*:*:*:*:*
References (MISC) https://github.com/nu11secur1ty/CVE-mitre/blob/main/CVE-2021-38758/README.MD - (MISC) https://github.com/nu11secur1ty/CVE-mitre/blob/main/CVE-2021-38758/README.MD - Broken Link
References (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38758 - (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38758 - Broken Link
References (MISC) https://attackerkb.com/topics/XuEb81tsid/online-catering-reservation-dt-food-catering-by-oretnom23-v1-0-sql-injection---login - (MISC) https://attackerkb.com/topics/XuEb81tsid/online-catering-reservation-dt-food-catering-by-oretnom23-v1-0-sql-injection---login - Third Party Advisory
References (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/Online-Catering-Reservation-DT-Food-Catering - (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/Online-Catering-Reservation-DT-Food-Catering - Exploit, Third Party Advisory

31 Aug 2021, 12:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/nu11secur1ty/CVE-mitre/blob/main/CVE-2021-38758/README.MD -
  • (MISC) https://attackerkb.com/topics/XuEb81tsid/online-catering-reservation-dt-food-catering-by-oretnom23-v1-0-sql-injection---login -
  • (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/Online-Catering-Reservation-DT-Food-Catering -

27 Aug 2021, 10:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38758 -
Summary Directory traversal in Online Catering Reservation System due to lack of validation in index.php. Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.

24 Aug 2021, 11:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://github.com/dumpling-soup/Online-Catering-Reservation-DT/blob/main/README.md - (MISC) https://github.com/dumpling-soup/Online-Catering-Reservation-DT/blob/main/README.md - Exploit, Third Party Advisory
CWE CWE-20
CWE-22
CPE cpe:2.3:a:online_catering_reservation_system_project:online_catering_reservation_system:-:*:*:*:*:*:*:*

16 Aug 2021, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-16 14:15

Updated : 2024-11-21 06:18


NVD link : CVE-2021-38758

Mitre link : CVE-2021-38758

CVE.ORG link : CVE-2021-38758


JSON object : View

Products Affected

online_catering_reservation_system_project

  • online_catering_reservation_system
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')