A vulnerability classified as critical was found in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection.
This vulnerability is tracked as CVE-2025-9744. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as critical, has been found in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection.
This vulnerability is listed as CVE-2025-9745. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as problematic, was found in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-9746. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Koillection up to 1.6.18 and classified as problematic. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-9747. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
The vendor explains: "I ended up switching to a newer CSRF handling using stateless token."
A vulnerability was found in Tenda CH22 1.0.0.1. It has been declared as critical. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument ipsecno can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2025-9748. The attack may be performed from remote. There is no available exploit.
A vulnerability labeled as critical has been found in PowerPhlogger 2.0.9/2.2.1/2.2.2a. Affected by this issue is some unknown functionality of the file showhits.php3. Such manipulation of the argument rel_path leads to improper privilege management.
This vulnerability is documented as CVE-2002-1885. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability described as critical has been identified in Gregory Kokanosky phpMyNewsletter 0.6.10. This vulnerability affects unknown code of the file customize.php. Executing manipulation of the argument l can lead to improper privilege management.
This vulnerability appears as CVE-2002-1887. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability was found in phpBB 2.0.3. It has been classified as problematic. Affected is an unknown function of the file viewtopic.php. The manipulation of the argument highlight leads to basic cross site scripting.
This vulnerability is referenced as CVE-2002-1894. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability has been found in w-Agora 4.1.1/4.1.2/4.1.3 and classified as critical. Impacted is an unknown function. This manipulation of the argument inc_dir causes improper privilege management.
The identification of this vulnerability is CVE-2002-1878. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability marked as problematic has been reported in Pinboard 1.0. Impacted is an unknown function of the component Tasklist Handler. The manipulation leads to basic cross site scripting.
This vulnerability is documented as CVE-2002-1900. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in Markus Triska CGIForum up to 1.0.5. The impacted element is an unknown function of the component Post Handler. This manipulation causes infinite loop.
This vulnerability appears as CVE-2002-1902. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Microsoft IIS 5.0/5.1. It has been classified as problematic. This affects an unknown part of the component HTTP Request Handler. This manipulation of the argument Host with the input / causes denial of service.
The identification of this vulnerability is CVE-2002-1908. It is possible to initiate the attack remotely. There is no exploit available.