Show filters
46 Total Results
Displaying 1-10 of 46
Sort by:
Attacker Value
Unknown

CVE-2023-33569

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.
Attacker Value
Unknown

CVE-2023-2962

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230150 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-33440

Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.
Attacker Value
Unknown

CVE-2023-33439

Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.
Attacker Value
Unknown

CVE-2023-32700

Disclosure Date: May 20, 2023 (last updated October 08, 2023)
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
Attacker Value
Unknown

CVE-2023-31845

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
Attacker Value
Unknown

CVE-2023-31844

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.
Attacker Value
Unknown

CVE-2023-31843

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.
Attacker Value
Unknown

CVE-2023-31842

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.
Attacker Value
Unknown

CVE-2023-32668

Disclosure Date: May 11, 2023 (last updated October 08, 2023)
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.