Show filters
252 Total Results
Displaying 51-60 of 252
Sort by:
Attacker Value
Unknown
CVE-2024-2940
Disclosure Date: March 27, 2024 (last updated February 20, 2025)
A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258031.
0
Attacker Value
Unknown
CVE-2024-2939
Disclosure Date: March 27, 2024 (last updated February 20, 2025)
A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258030 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-2938
Disclosure Date: March 27, 2024 (last updated February 21, 2025)
A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258029 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-47020
Disclosure Date: February 08, 2024 (last updated February 15, 2024)
Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.
0
Attacker Value
Unknown
CVE-2023-47022
Disclosure Date: February 06, 2024 (last updated February 14, 2024)
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
0
Attacker Value
Unknown
CVE-2023-47024
Disclosure Date: January 20, 2024 (last updated February 10, 2024)
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types.
0
Attacker Value
Unknown
CVE-2021-31314
Disclosure Date: January 20, 2024 (last updated January 27, 2024)
File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.
0
Attacker Value
Unknown
CVE-2023-45121
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45120
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45119
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database.
0