Show filters
53 Total Results
Displaying 21-30 of 53
Sort by:
Attacker Value
Unknown
CVE-2024-6009
Disclosure Date: June 15, 2024 (last updated February 26, 2025)
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268699.
0
Attacker Value
Unknown
CVE-2024-0726
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin_login.php of the component Admin Login Module. The manipulation of the argument msg with the input test%22%3Cscript%3Ealert(%27Torada%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251549 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-48434
Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-48433
Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-35867
Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
0
Attacker Value
Unknown
CVE-2023-5185
Disclosure Date: September 28, 2023 (last updated February 25, 2025)
Gym Management System Project v1.0 is vulnerable to
an Insecure File Upload vulnerability on the 'file'
parameter of profile/i.php page, allowing an
authenticated attacker to obtain Remote Code Execution
on the server hosting the application.
0
Attacker Value
Unknown
CVE-2023-43144
Disclosure Date: September 22, 2023 (last updated February 25, 2025)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
0
Attacker Value
Unknown
CVE-2023-1725
Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery.This issue affects Project Management System: before 4.09.31.125.
0
Attacker Value
Unknown
CVE-2022-43213
Disclosure Date: November 23, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
0
Attacker Value
Unknown
CVE-2022-43212
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
0