Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-22922
Disclosure Date: January 25, 2024 (last updated January 30, 2024)
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
0
Attacker Value
Unknown
CVE-2024-0652
Disclosure Date: January 18, 2024 (last updated January 20, 2024)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251378 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0651
Disclosure Date: January 18, 2024 (last updated January 20, 2024)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0650
Disclosure Date: January 18, 2024 (last updated January 25, 2024)
A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file dataset.php of the component URL Handler. The manipulation of the argument name with the input "><script>alert('torada')</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251376.
0
Attacker Value
Unknown
CVE-2023-5918
Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Visitor Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244308.
0
Attacker Value
Unknown
CVE-2022-38265
Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /avms/edit-apartment.php.
0
Attacker Value
Unknown
CVE-2020-25761
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.
0
Attacker Value
Unknown
CVE-2020-25760
Disclosure Date: September 30, 2020 (last updated February 22, 2025)
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
0