Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2022-33880

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.
Attacker Value
Unknown

CVE-2020-28441

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.
Attacker Value
Unknown

CVE-2020-28461

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.
Attacker Value
Unknown

CVE-2022-30929

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
Attacker Value
Unknown

CVE-2021-42860

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API specification
Attacker Value
Unknown

CVE-2021-42859

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release
Attacker Value
Unknown

CVE-2021-44321

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
Attacker Value
Unknown

CVE-2020-18999

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
Attacker Value
Unknown

CVE-2020-18998

Disclosure Date: August 27, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
Attacker Value
Unknown

CVE-2020-28460

Disclosure Date: December 22, 2020 (last updated February 22, 2025)
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.