Show filters
78 Total Results
Displaying 71-78 of 78
Sort by:
Attacker Value
Unknown

CVE-2020-28173

Disclosure Date: March 31, 2021 (last updated February 22, 2025)
Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/.
Attacker Value
Unknown

CVE-2020-26051

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.
Attacker Value
Unknown

CVE-2019-1010028

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.
0
Attacker Value
Unknown

CVE-2018-6863

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.
0
Attacker Value
Unknown

CVE-2014-6967

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Albion College (aka com.vivomobile.albioncollege) application 2.1.16 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2009-2218

Disclosure Date: June 25, 2009 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the home parameter to (1) i_head.php, (2) i_nav.php, (3) user_new_2.php, or (4) house/myrents.php; or (5) allbooks.php, (6) home.php, or (7) mybooks.php in books/. NOTE: house/myrents.php was also separately reported as a local file inclusion issue.
0
Attacker Value
Unknown

CVE-2009-2219

Disclosure Date: June 25, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the (1) _SESSION[handle] parameter to (a) home.php, (b) books/allbooks.php, or (c) books/home.php; or the (2) home parameter to (d) i_head.php or (e) i_nav.php, or (f) allbooks.php, (g) home.php, or (h) i_nav.php in books/.
0
Attacker Value
Unknown

CVE-2009-2096

Disclosure Date: June 17, 2009 (last updated October 04, 2023)
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.
0