Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2022-30411

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.
Attacker Value
Unknown

CVE-2022-30408

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.
Attacker Value
Unknown

CVE-2021-25208

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload to updatepackage.php.
Attacker Value
Unknown

CVE-2021-25213

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.
Attacker Value
Unknown

CVE-2020-29205

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
Attacker Value
Unknown

CVE-2020-24203

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.