Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Very High
CVE-2021-42169
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
3
Attacker Value
Unknown
CVE-2023-1113
Disclosure Date: March 01, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222073 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-23416
Disclosure Date: July 28, 2021 (last updated February 23, 2025)
This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.
0
Attacker Value
Unknown
CVE-2021-32773
Disclosure Date: July 20, 2021 (last updated February 23, 2025)
Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause system modules to incorrectly use attacker-created modules instead of their intended dependencies. This could allow system functions to be controlled by the attacker, giving access to facilities intended to be restricted. This problem is fixed in Racket version 8.2. A workaround is available, depending on system settings. For systems that provide arbitrary Racket evaluation, external sandboxing such as containers limit the impact of the problem. For multi-user evaluation systems, such as the `handin-server` system, it is not possible to work around this problem and upgrading is required.
0
Attacker Value
Unknown
CVE-2019-8255
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2018-3735
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
0
Attacker Value
Unknown
CVE-2016-4164
Disclosure Date: June 16, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Adobe Brackets before 1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4165
Disclosure Date: June 16, 2016 (last updated November 25, 2024)
The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input.
0
Attacker Value
Unknown
CVE-2010-0945
Disclosure Date: March 08, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
0