Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2022-3458
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.
0
Attacker Value
Unknown
CVE-2015-3423
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9) filter_INSERT_COUNT, (10) filter_MINOR_FALLOUT, (11) filter_UPDATE_COUNT, (12) sort, or (13) sessid parameter.
0
Attacker Value
Unknown
CVE-2015-2207
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (5) parent, (6) circuit, (7) return, (8) xname, or (9) mpTransactionId parameter.
0
Attacker Value
Unknown
CVE-2015-3425
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.
0
Attacker Value
Unknown
CVE-2015-3424
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
0
Attacker Value
Unknown
CVE-2018-3072
Disclosure Date: July 18, 2018 (last updated November 27, 2024)
Vulnerability in the PeopleSoft HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft HRMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft HRMS accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
0
Attacker Value
Unknown
CVE-2017-14848
Disclosure Date: October 03, 2017 (last updated November 26, 2024)
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
0
Attacker Value
Unknown
CVE-2001-0134
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
0