Show filters
191 Total Results
Displaying 111-120 of 191
Sort by:
Attacker Value
Unknown
CVE-2021-45348
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).
0
Attacker Value
Unknown
CVE-2021-44598
Disclosure Date: December 26, 2021 (last updated February 23, 2025)
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.
0
Attacker Value
Unknown
CVE-2021-44280
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.
0
Attacker Value
Unknown
CVE-2021-37442
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
0
Attacker Value
Unknown
CVE-2021-37444
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
0
Attacker Value
Unknown
CVE-2021-37449
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
0
Attacker Value
Unknown
CVE-2021-37443
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
0
Attacker Value
Unknown
CVE-2021-37448
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
0
Attacker Value
Unknown
CVE-2021-37451
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
0
Attacker Value
Unknown
CVE-2021-37450
Disclosure Date: July 25, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
0