Show filters
1,653 Total Results
Displaying 181-190 of 1,653
Sort by:
Attacker Value
Unknown

CVE-2024-43774

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
Attacker Value
Unknown

CVE-2024-43773

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
Attacker Value
Unknown

CVE-2024-43772

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
Attacker Value
Unknown

CVE-2024-8328

Disclosure Date: August 30, 2024 (last updated February 26, 2025)
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.
Attacker Value
Unknown

CVE-2024-8327

Disclosure Date: August 30, 2024 (last updated February 26, 2025)
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.
Attacker Value
Unknown

CVE-2024-45045

Disclosure Date: August 29, 2024 (last updated February 26, 2025)
Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject JavaScript via url encoded values in links contained in documents. Since the Android JavaScript interface allows access to internal functions, the likelihood that the app could be compromised via this vulnerability is considered high. Non-mobile variants are not affected. Mobile variants should update to the latest version provided by the platform appstore. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2024-8218

Disclosure Date: August 27, 2024 (last updated February 26, 2025)
A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8169

Disclosure Date: August 26, 2024 (last updated February 26, 2025)
A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8168

Disclosure Date: August 26, 2024 (last updated February 26, 2025)
A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-42918

Disclosure Date: August 23, 2024 (last updated February 26, 2025)
itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADDRES, CONTACTNO, COMPANYNAME and COMPANYCONTACTNO parameters in controller.php.