CVE-2023-1468 – SourceCodester Student Study Center Desk Management System Report sql injection
https://notcve.org/view.php?id=CVE-2023-1468
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the component Report Handler. The manipulation of the argument date_from/date_to leads to sql injection. The attack can be launched remotely. • https://vuldb.com/?ctiid.223327 https://vuldb.com/?id.223327 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-1467 – SourceCodester Student Study Center Desk Management System POST Parameter path traversal
https://notcve.org/view.php?id=CVE-2023-1467
A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the input C%3A%2Ffoo.txt leads to path traversal. It is possible to launch the attack remotely. • https://vuldb.com/?ctiid.223326 https://vuldb.com/?id.223326 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2023-1466 – SourceCodester Student Study Center Desk Management System view_student sql injection
https://notcve.org/view.php?id=CVE-2023-1466
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(SLEEP(5)))FWlC) AND 'butz'='butz leads to sql injection. • https://vuldb.com/?ctiid.223325 https://vuldb.com/?id.223325 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-1407 – SourceCodester Student Study Center Desk Management System manage_user.php sql injection
https://notcve.org/view.php?id=CVE-2023-1407
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://s1.ax1x.com/2023/03/15/pp1gd8x.png https://vuldb.com/?ctiid.223111 https://vuldb.com/?id.223111 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •