Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2021-44098
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
0
Attacker Value
Unknown
CVE-2021-44096
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
0
Attacker Value
Unknown
CVE-2020-36115
Disclosure Date: January 28, 2021 (last updated November 28, 2024)
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.
0
Attacker Value
Unknown
CVE-2020-35263
Disclosure Date: January 26, 2021 (last updated November 28, 2024)
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-29228
Disclosure Date: December 30, 2020 (last updated November 28, 2024)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
0
Attacker Value
Unknown
CVE-2020-29231
Disclosure Date: December 30, 2020 (last updated November 28, 2024)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.
0
Attacker Value
Unknown
CVE-2020-29230
Disclosure Date: December 30, 2020 (last updated November 28, 2024)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.
0
Attacker Value
Unknown
CVE-2020-29472
Disclosure Date: December 24, 2020 (last updated November 28, 2024)
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-29474
Disclosure Date: December 24, 2020 (last updated November 28, 2024)
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-35252
Disclosure Date: December 23, 2020 (last updated November 28, 2024)
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
0