Show filters
218 Total Results
Displaying 161-170 of 218
Sort by:
Attacker Value
Unknown

CVE-2023-51800

Disclosure Date: February 29, 2024 (last updated December 18, 2024)
Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.
Attacker Value
Unknown

CVE-2024-25310

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
Attacker Value
Unknown

CVE-2024-25313

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.
Attacker Value
Unknown

CVE-2024-25312

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
Attacker Value
Unknown

CVE-2024-25309

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
Attacker Value
Unknown

CVE-2024-25308

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
Attacker Value
Unknown

CVE-2024-25306

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
Attacker Value
Unknown

CVE-2024-25305

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
Attacker Value
Unknown

CVE-2024-25304

Disclosure Date: February 09, 2024 (last updated February 13, 2024)
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
Attacker Value
Unknown

CVE-2023-3339

Disclosure Date: June 21, 2023 (last updated February 25, 2025)
A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file exam-delete.php. The manipulation of the argument test_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232015.