Show filters
570 Total Results
Displaying 151-160 of 570
Sort by:
Attacker Value
Unknown
CVE-2022-31996
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=.
0
Attacker Value
Unknown
CVE-2022-30490
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
0
Attacker Value
Unknown
CVE-2022-1589
Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
0
Attacker Value
Unknown
CVE-2022-29450
Disclosure Date: May 27, 2022 (last updated February 23, 2025)
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
0
Attacker Value
Unknown
CVE-2022-30428
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
0
Attacker Value
Unknown
CVE-2022-30427
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
0
Attacker Value
Unknown
CVE-2022-30456
Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.
0
Attacker Value
Unknown
CVE-2022-30455
Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.
0
Attacker Value
Unknown
CVE-2022-1817
Disclosure Date: May 23, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.
0
Attacker Value
Unknown
CVE-2021-28290
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
0