Show filters
732 Total Results
Displaying 201-210 of 732
Sort by:
Attacker Value
Unknown

CVE-2022-3942

Disclosure Date: November 11, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-29836

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain parameters to point to random locations on the file system. This could also allow the attacker to initiate the installation of custom packages at these locations. This can only be exploited once the attacker has been authenticated to the device. This issue affects: Western Digital My Cloud Home and My Cloud Home Duo versions prior to 8.11.0-113 on Linux; SanDisk ibi versions prior to 8.11.0-113 on Linux.
Attacker Value
Unknown

CVE-2022-43351

Disclosure Date: November 07, 2022 (last updated December 22, 2024)
Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
Attacker Value
Unknown

CVE-2022-43350

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry.
Attacker Value
Unknown

CVE-2022-43352

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.
Attacker Value
Unknown

CVE-2022-3868

Disclosure Date: November 05, 2022 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an unknown function of the file /php-sms/classes/Master.php?f=save_quote. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213012.
Attacker Value
Unknown

CVE-2022-43354

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.
Attacker Value
Unknown

CVE-2022-43353

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
Attacker Value
Unknown

CVE-2022-43355

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.
Attacker Value
Unknown

CVE-2022-3672

Disclosure Date: October 26, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1.0. This issue affects some unknown processing of the file /php-sms/classes/SystemSettings.php. The manipulation of the argument name/shortname leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-212015.