CVE-2022-28080 – Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
https://notcve.org/view.php?id=CVE-2022-28080
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. Se ha detectado que Royal Event Management System versión v1.0, contiene una vulnerabilidad de inyección SQL por medio del parámetro todate Royal Event Management System version 1.0 suffers from a remote SQL injection vulnerability. • https://www.exploit-db.com/exploits/50934 http://packetstormsecurity.com/files/167123/Royal-Event-Management-System-1.0-SQL-Injection.html https://github.com/erengozaydin/Royal-Event-Management-System-todate-SQL-Injection-Authenticated https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html https://www.sourcecodester.com/sites/default/files/download/oretnom23/Royal%20Event.zip • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-25114
https://notcve.org/view.php?id=CVE-2022-25114
Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php. Se ha detectado que Event Management versión v1.0, contiene una vulnerabilidad de tipo cross-site scripting (XSS) reflejado por medio del parámetro full_name bajo el archivo register.php • https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/PuneethReddyHC/event-management-1.0 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-18795 – School Event Management System 1.0 - SQL Injection
https://notcve.org/view.php?id=CVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. School Event Management System 1.0 tiene una inyección SQL mediante el parámetro id en student/index.php o event/index.php. School Event Management System version 1.0 suffers from a remote SQL injection vulnerability. • https://www.exploit-db.com/exploits/45722 http://packetstormsecurity.com/files/150014/School-Event-Management-System-1.0-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-18794 – School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
https://notcve.org/view.php?id=CVE-2018-18794
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. School Event Management System 1.0 permite Cross-Site Request Forgery (CSRF) mediante user/controller.php?action=edit. School Event Management System version 1.0 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/45724 http://packetstormsecurity.com/files/150007/School-Event-Management-System-1.0-Cross-Site-Request-Forgery.html • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2018-18793 – School Event Management System 1.0 - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. School Event Management System 1.0 permite la subida de archivos arbitrarios mediante event/controller.php?action=photos. School Event Management System version 1.0 suffers from a remote shell upload vulnerability. • https://www.exploit-db.com/exploits/45723 http://packetstormsecurity.com/files/150006/School-Event-Management-System-1.0-Shell-Upload.html • CWE-434: Unrestricted Upload of File with Dangerous Type •