Show filters
3,812 Total Results
Displaying 201-210 of 3,812
Sort by:
Attacker Value
Unknown

CVE-2024-5135

Disclosure Date: May 20, 2024 (last updated February 23, 2025)
A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265211.
Attacker Value
Unknown

CVE-2024-5066

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-5065

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.
0
Attacker Value
Unknown

CVE-2024-5064

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.
0
Attacker Value
Unknown

CVE-2024-5063

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-34423

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpbits Forty Four – 404 Plugin for WordPress allows Stored XSS.This issue affects Forty Four – 404 Plugin for WordPress: from n/a through 1.4.
0
Attacker Value
Unknown

CVE-2024-3096

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
0
Attacker Value
Unknown

CVE-2024-2757

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.
0
Attacker Value
Unknown

CVE-2024-2756

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
0
Attacker Value
Unknown

CVE-2024-1874

Disclosure Date: April 29, 2024 (last updated February 14, 2025)
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
0