Show filters
78 Total Results
Displaying 61-70 of 78
Sort by:
Attacker Value
Unknown
CVE-2022-28079
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
0
Attacker Value
Unknown
CVE-2022-26615
Disclosure Date: April 05, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
0
Attacker Value
Unknown
CVE-2022-1078
Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.
0
Attacker Value
Unknown
CVE-2022-1075
Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.
0
Attacker Value
Unknown
CVE-2021-44593
Disclosure Date: January 21, 2022 (last updated October 07, 2023)
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
0
Attacker Value
Unknown
CVE-2021-26232
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.
0
Attacker Value
Unknown
CVE-2020-25409
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
0
Attacker Value
Unknown
CVE-2020-25408
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.
0
Attacker Value
Unknown
CVE-2021-24254
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.
0
Attacker Value
Unknown
CVE-2020-28172
Disclosure Date: March 31, 2021 (last updated February 22, 2025)
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.
0