Show filters
114 Total Results
Displaying 81-90 of 114
Sort by:
Attacker Value
Unknown

CVE-2022-29988

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
Attacker Value
Unknown

CVE-2022-29987

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-29986

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.
Attacker Value
Unknown

CVE-2022-29985

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
Attacker Value
Unknown

CVE-2022-28094

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
Attacker Value
Unknown

CVE-2022-28093

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-28115

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
Attacker Value
Unknown

CVE-2021-42835

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).
Attacker Value
Unknown

CVE-2020-5742

Disclosure Date: June 15, 2020 (last updated November 28, 2024)
Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
Attacker Value
Unknown

CVE-2020-5740

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.