Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-7813

Disclosure Date: August 15, 2024 (last updated August 20, 2024)
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently protected credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-32405

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4
Attacker Value
Unknown

CVE-2022-32404

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3
Attacker Value
Unknown

CVE-2022-32403

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4
Attacker Value
Unknown

CVE-2022-32402

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4
Attacker Value
Unknown

CVE-2022-32401

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4
Attacker Value
Unknown

CVE-2022-32400

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.
Attacker Value
Unknown

CVE-2022-32399

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
Attacker Value
Unknown

CVE-2022-32398

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
Attacker Value
Unknown

CVE-2022-32397

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4