5 results (0.014 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html. Un problema en Employee Managment System v1.0 permite a los atacantes eludir la autenticación mediante la inyección de un payload manipulado en los parámetros de correo electrónico y contraseña en /alogin.html. • https://github.com/BurakSevben/CVEs/blob/main/Employee%20Management%20System/Employee%20Managment%20System%20-%20Authentication%20Bypass.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. Se descubrió que Employee Managment System v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro pwd en /aprocess.php. • https://github.com/BurakSevben/CVEs/blob/main/Employee%20Management%20System/Employee%20Managment%20System%20-%20SQL%20Injection%20-%202.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php. Se descubrió que Employee Managment System v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro mailud en /aprocess.php. • https://github.com/BurakSevben/CVEs/blob/main/Employee%20Management%20System/Employee%20Managment%20System%20-%20SQL%20Injection%20-%201.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php. Se descubrió que Employee Managment System v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro id en /edit.php. • https://github.com/BurakSevben/CVEs/blob/main/Employee%20Management%20System/Employee%20Managment%20System%20-%20SQL%20Injection%20-%203.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 1

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php. Se descubrió que Employee Managment System v1.0 contenía una vulnerabilidad de inyección SQL a través del parámetro id en /delete.php. • https://github.com/BurakSevben/CVEs/blob/main/Employee%20Management%20System/Employee%20Managment%20System%20-%20SQL%20Injection%20-%204.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •