Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown
CVE-2021-25212
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
0
Attacker Value
Unknown
CVE-2021-25210
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
0
Attacker Value
Unknown
CVE-2021-24365
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
0
Attacker Value
Unknown
CVE-2021-24366
Disclosure Date: June 21, 2021 (last updated November 08, 2023)
The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2020-29214
Disclosure Date: June 15, 2021 (last updated February 22, 2025)
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
0
Attacker Value
Unknown
CVE-2020-28070
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
0
Attacker Value
Unknown
CVE-2020-28071
Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
0
Attacker Value
Unknown
CVE-2020-28072
Disclosure Date: December 15, 2020 (last updated February 22, 2025)
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.
0
Attacker Value
Unknown
CVE-2020-9022
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.
0
Attacker Value
Unknown
CVE-2019-17661
Disclosure Date: November 08, 2019 (last updated February 15, 2024)
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first or last name, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.
0