Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2024-4801

Disclosure Date: May 14, 2024 (last updated February 12, 2025)
A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263921 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-4800

Disclosure Date: May 14, 2024 (last updated February 12, 2025)
A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263920.
Attacker Value
Unknown

CVE-2024-4799

Disclosure Date: May 14, 2024 (last updated February 12, 2025)
A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.
Attacker Value
Unknown

CVE-2022-39180

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page
Attacker Value
Unknown

CVE-2022-39179

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
Attacker Value
Unknown

CVE-2022-32420

Disclosure Date: July 01, 2022 (last updated October 07, 2023)
College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-30404

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.
Attacker Value
Unknown

CVE-2022-28079

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
Attacker Value
Unknown

CVE-2022-26615

Disclosure Date: April 05, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
Attacker Value
Unknown

CVE-2022-1078

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.