CVE-2023-2695 – SourceCodester Online Exam System POST Parameter data sql injection
https://notcve.org/view.php?id=CVE-2023-2695
A vulnerability was found in SourceCodester Online Exam System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /kelas/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. • https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/img/kelas_data.png https://vuldb.com/?ctiid.228976 https://vuldb.com/?id.228976 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2694 – SourceCodester Online Exam System POST Parameter data sql injection
https://notcve.org/view.php?id=CVE-2023-2694
A vulnerability was found in SourceCodester Online Exam System 1.0. It has been classified as critical. This affects an unknown part of the file /dosen/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/img/dosen_data.png https://vuldb.com/?ctiid.228975 https://vuldb.com/?id.228975 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2693 – SourceCodester Online Exam System POST Parameter data sql injection
https://notcve.org/view.php?id=CVE-2023-2693
A vulnerability was found in SourceCodester Online Exam System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mahasiswa/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/img/mahasiswa_data.png https://vuldb.com/?ctiid.228974 https://vuldb.com/?id.228974 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-2642 – SourceCodester Online Exam System GET Parameter updateCourse.php sql injection
https://notcve.org/view.php?id=CVE-2023-2642
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. This affects an unknown part of the file adminpanel/admin/facebox_modal/updateCourse.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/sushanburanxisha/cve/blob/main/SQLi-1.md https://vuldb.com/?ctiid.228771 https://vuldb.com/?id.228771 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-2707 – SourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection
https://notcve.org/view.php?id=CVE-2022-2707
A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/faculty_sched.php. The manipulation of the argument faculty with the input ' OR (SELECT 2078 FROM(SELECT COUNT(*),CONCAT(0x716a717071,(SELECT (ELT(2078=2078,1))),0x717a706a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- uYCM leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/anx0ing/CVE_demo/blob/main/2022/Online%20Class%20and%20Exam%20Scheduling%20System-SQL%20injections.md https://vuldb.com/?id.205831 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •