Show filters
252 Total Results
Displaying 61-70 of 252
Sort by:
Attacker Value
Unknown
CVE-2023-45118
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45117
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45116
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45115
Disclosure Date: December 21, 2023 (last updated January 02, 2024)
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-5119
Disclosure Date: November 20, 2023 (last updated November 28, 2023)
The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).
0
Attacker Value
Unknown
CVE-2023-6133
Disclosure Date: November 15, 2023 (last updated December 01, 2023)
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.
0
Attacker Value
Unknown
CVE-2023-46963
Disclosure Date: November 04, 2023 (last updated November 15, 2023)
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.
0
Attacker Value
Unknown
CVE-2023-45111
Disclosure Date: November 02, 2023 (last updated November 09, 2023)
Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.
0
Attacker Value
Unknown
CVE-2023-45203
Disclosure Date: November 01, 2023 (last updated November 09, 2023)
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
0
Attacker Value
Unknown
CVE-2023-45202
Disclosure Date: November 01, 2023 (last updated November 09, 2023)
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
0