Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
High
CVE-2020-10225
Disclosure Date: March 08, 2020 (last updated February 21, 2025)
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.
0
Attacker Value
Unknown
CVE-2024-8473
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.
0
Attacker Value
Unknown
CVE-2024-8472
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.
0
Attacker Value
Unknown
CVE-2024-8471
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.
0
Attacker Value
Unknown
CVE-2024-8470
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.
0
Attacker Value
Unknown
CVE-2024-8469
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.
0
Attacker Value
Unknown
CVE-2024-8468
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.
0
Attacker Value
Unknown
CVE-2024-8467
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.
0
Attacker Value
Unknown
CVE-2024-8466
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.
0
Attacker Value
Unknown
CVE-2024-8465
Disclosure Date: September 05, 2024 (last updated September 06, 2024)
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
0