Show filters
501 Total Results
Displaying 61-70 of 501
Sort by:
Attacker Value
Unknown

CVE-2024-39916

Disclosure Date: July 12, 2024 (last updated February 26, 2025)
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export in the default installation. The exports have the no_subtree_check option. The no_subtree_check option means that if a client performs a file operation, the server will only check if the requested file is on the correct filesystem, not if it is in the correct directory. This enables modifying files in /images, accessing other files on the same filesystem, and accessing files on other filesystems. This vulnerability is fixed in 1.5.10.30.
Attacker Value
Unknown

CVE-2024-39914

Disclosure Date: July 12, 2024 (last updated February 26, 2025)
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
0
Attacker Value
Unknown

CVE-2024-37873

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Attacker Value
Unknown

CVE-2024-37484

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manager: from n/a through 3.3.97.
Attacker Value
Unknown

CVE-2024-37224

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71.
Attacker Value
Unknown

CVE-2024-22232

Disclosure Date: June 27, 2024 (last updated February 26, 2025)
A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
0
Attacker Value
Unknown

CVE-2024-22231

Disclosure Date: June 27, 2024 (last updated February 26, 2025)
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.
0
Attacker Value
Unknown

CVE-2024-6196

Disclosure Date: June 20, 2024 (last updated February 26, 2025)
A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269168.
Attacker Value
Unknown

CVE-2024-6193

Disclosure Date: June 20, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file driverprofile.php. The manipulation of the argument driverid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269165 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-6016

Disclosure Date: June 15, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268724.