Show filters
169 Total Results
Displaying 161-169 of 169
Sort by:
Attacker Value
Unknown
CVE-2022-24572
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details.
0
Attacker Value
Unknown
CVE-2022-24571
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
0
Attacker Value
Unknown
CVE-2018-18795
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
0
Attacker Value
Unknown
CVE-2018-18794
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
0
Attacker Value
Unknown
CVE-2018-18793
Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
0
Attacker Value
Unknown
CVE-2014-1915
Disclosure Date: February 07, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update action to sw/admin_change_password.php or (2) unspecified victims for requests that add a topic or blog entry to sw/add_topic.php. NOTE: vector 2 can be leveraged to bypass the authentication requirements for exploiting vector 1 in CVE-2014-1914.
0
Attacker Value
Unknown
CVE-2014-1914
Disclosure Date: February 07, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2) nick parameter to sw/chat/message.php.
0
Attacker Value
Unknown
CVE-2014-1637
Disclosure Date: January 22, 2014 (last updated October 05, 2023)
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.
0
Attacker Value
Unknown
CVE-2014-1636
Disclosure Date: January 22, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to (1) admin_school_names.php, (2) admin_subjects.php, (3) admin_grades.php, (4) admin_terms.php, (5) admin_school_years.php, (6) admin_sgrades.php, (7) admin_media_codes_1.php, (8) admin_infraction_codes.php, (9) admin_generations.php, (10) admin_relations.php, (11) admin_titles.php, or (12) health_allergies.php in sw/.
0