Show filters
53 Total Results
Displaying 21-30 of 53
Sort by:
Attacker Value
Unknown

CVE-2024-6009

Disclosure Date: June 15, 2024 (last updated February 26, 2025)
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268699.
Attacker Value
Unknown

CVE-2024-0726

Disclosure Date: January 19, 2024 (last updated February 26, 2025)
A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin_login.php of the component Admin Login Module. The manipulation of the argument msg with the input test%22%3Cscript%3Ealert(%27Torada%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251549 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-48434

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-48433

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.
Attacker Value
Unknown

CVE-2023-35867

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Attacker Value
Unknown

CVE-2023-5185

Disclosure Date: September 28, 2023 (last updated February 25, 2025)
Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Attacker Value
Unknown

CVE-2023-43144

Disclosure Date: September 22, 2023 (last updated February 25, 2025)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
Attacker Value
Unknown

CVE-2023-1725

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125.
Attacker Value
Unknown

CVE-2022-43213

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
Attacker Value
Unknown

CVE-2022-43212

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.