Show filters
732 Total Results
Displaying 191-200 of 732
Sort by:
Attacker Value
Unknown

CVE-2022-29837

Disclosure Date: December 01, 2022 (last updated February 24, 2025)
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
Attacker Value
Unknown

CVE-2022-44296

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.
Attacker Value
Unknown

CVE-2022-44295

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.
Attacker Value
Unknown

CVE-2022-44294

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.
Attacker Value
Unknown

CVE-2022-44151

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
Attacker Value
Unknown

CVE-2022-44096

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
Attacker Value
Unknown

CVE-2022-45214

Disclosure Date: November 28, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes/Login.php.
Attacker Value
Unknown

CVE-2022-44278

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-42989

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
Attacker Value
Unknown

CVE-2022-3992

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-213571.