Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2021-25212

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
Attacker Value
Unknown

CVE-2021-25210

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
Attacker Value
Unknown

CVE-2020-29214

Disclosure Date: June 15, 2021 (last updated February 22, 2025)
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
Attacker Value
Unknown

CVE-2020-28070

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
Attacker Value
Unknown

CVE-2020-28071

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
Attacker Value
Unknown

CVE-2020-28072

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.
Attacker Value
Unknown

CVE-2008-2117

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.
0
Attacker Value
Unknown

CVE-2008-2118

Disclosure Date: May 08, 2008 (last updated October 04, 2023)
SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2007-6184

Disclosure Date: November 30, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter.
0
Attacker Value
Unknown

CVE-2007-6127

Disclosure Date: November 26, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.
0