Show filters
3,812 Total Results
Displaying 201-210 of 3,812
Sort by:
Attacker Value
Unknown
CVE-2024-5135
Disclosure Date: May 20, 2024 (last updated February 23, 2025)
A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265211.
0
Attacker Value
Unknown
CVE-2024-5066
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-5065
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.
0
Attacker Value
Unknown
CVE-2024-5064
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.
0
Attacker Value
Unknown
CVE-2024-5063
Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-34423
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpbits Forty Four – 404 Plugin for WordPress allows Stored XSS.This issue affects Forty Four – 404 Plugin for WordPress: from n/a through 1.4.
0
Attacker Value
Unknown
CVE-2024-3096
Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
0
Attacker Value
Unknown
CVE-2024-2757
Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
0
Attacker Value
Unknown
CVE-2024-2756
Disclosure Date: April 29, 2024 (last updated February 14, 2025)
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
0
Attacker Value
Unknown
CVE-2024-1874
Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
0