Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-0652

Disclosure Date: January 18, 2024 (last updated February 26, 2025)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251378 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0651

Disclosure Date: January 18, 2024 (last updated February 26, 2025)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-4832

Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection.This issue affects Company Management: before 3072 .
Attacker Value
Unknown

CVE-2018-19924

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.
0
Attacker Value
Unknown

CVE-2018-19923

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
0
Attacker Value
Unknown

CVE-2018-19925

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
0
Attacker Value
Unknown

CVE-2018-19654

Disclosure Date: November 29, 2018 (last updated November 27, 2024)
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as demonstrated by use of the test%c2 string when a test account already exists.