Aggregator
CVE-2015-3542 | phpoffice PHPExcel up to 1.8.0 xml external entity reference
1 year 5 months ago
A vulnerability was found in phpoffice PHPExcel up to 1.8.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2015-3542. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-20460 | Epson Expression Home XP255 20.08.FM10I8 POST Request cross-site request forgery
1 year 5 months ago
A vulnerability was found in Epson Expression Home XP255 20.08.FM10I8. It has been classified as problematic. Affected is an unknown function of the component POST Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2019-20460. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2019-20462 | Alecto IVM-100 2019-11-12 Serial Interface information disclosure
1 year 5 months ago
A vulnerability was found in Alecto IVM-100 2019-11-12 and classified as problematic. This issue affects some unknown processing of the component Serial Interface. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2019-20462. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2019-20461 | Alecto IVM-100 2019-11-12 UDP Protocol improper authentication
1 year 5 months ago
A vulnerability has been found in Alecto IVM-100 2019-11-12 and classified as problematic. This vulnerability affects unknown code of the component UDP Protocol Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2019-20461. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-20472 | One2Track 2019-12-08 empty password in configuration file
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in One2Track 2019-12-08. This affects an unknown part. The manipulation leads to empty password in configuration file.
This vulnerability is uniquely identified as CVE-2019-20472. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2019-20469 | One2Track 2019-12-08 amr File information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in One2Track 2019-12-08. Affected by this issue is some unknown functionality of the component amr File Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2019-20469. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-11000 | CodeAstro Real Estate Management System 1.0 About Us Page /aboutedit.php aimage unrestricted upload
1 year 5 months ago
A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload.
This vulnerability is known as CVE-2024-11000. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10999 | CodeAstro Real Estate Management System 1.0 About Us Page /aboutadd.php aimage unrestricted upload
1 year 5 months ago
A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload.
This vulnerability is traded as CVE-2024-10999. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
A Threat Actor Has Allegedly Leaked Data of Orgchem KPI
1 year 5 months ago
A Threat Actor Has Allegedly Leaked Data of Orgchem KPI
Dark Web Informer
Submit #438603: CodeAstro Real Estate Management System 1.0 Arbitrary Authenticated File Upload Leading to RCE [Accepted]
1 year 5 months ago
Submit #438603 / VDB-283465
egsec
CVE-2024-10998 | 1000 Projects Bookstore Management System 1.0 process_category_add.php cat sql injection
1 year 5 months ago
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/process_category_add.php. The manipulation of the argument cat leads to sql injection.
The identification of this vulnerability is CVE-2024-10998. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10997 | 1000 Projects Bookstore Management System 1.0 /book_list.php id sql injection
1 year 5 months ago
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /book_list.php. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-10997. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10996 | 1000 Projects Bookstore Management System 1.0 process_category_edit.php cat sql injection
1 year 5 months ago
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/process_category_edit.php. The manipulation of the argument cat leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10996. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10995 | Codezips Hospital Appointment System 1.0 /removeDoctorResult.php Name sql injection
1 year 5 months ago
A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /removeDoctorResult.php. The manipulation of the argument Name leads to sql injection.
This vulnerability is handled as CVE-2024-10995. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #438409: 1000 Projects Bookstore Management System PHP MySQL Project V1.0 SQL Injection [Accepted]
1 year 5 months ago
Submit #438409 / VDB-283463
smileeeee
Submit #438146: 1000 Projects Bookstore Management System v1.0 v1.0 SQL Injection [Accepted]
1 year 5 months ago
Submit #438146 / VDB-283462
SunYihang
Submit #438105: 1000 Projects Bookstore Management System PHP MySQL Project V1.0 SQL Injection [Accepted]
1 year 5 months ago
Submit #438105 / VDB-283461
action202411
CVE-2024-10994 | Codezips Online Institute Management System 1.0 /edit_user.php image unrestricted upload
1 year 5 months ago
A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit_user.php. The manipulation of the argument image leads to unrestricted upload.
This vulnerability is known as CVE-2024-10994. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10993 | Codezips Online Institute Management System 1.0 /manage_website.php website_image unrestricted upload
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /manage_website.php. The manipulation of the argument website_image leads to unrestricted upload.
This vulnerability is traded as CVE-2024-10993. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com