Page 4 of 18 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view. Attendance Monitoring System 1.0 tiene una inyección SQL mediante el parámetro "id" en student/index.php? • https://www.exploit-db.com/exploits/45727 http://packetstormsecurity.com/files/150010/School-Attendance-Monitoring-System-1.0-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. School Attendance Monitoring System 1.0 tiene Cross-Site Request Forgery (CSRF) mediante event/controller.php?action=photos. School Attendance Monitoring System version 1.0 suffers from a remote shell upload vulnerability. • https://www.exploit-db.com/exploits/45726 http://packetstormsecurity.com/files/150009/School-Attendance-Monitoring-System-1.0-Shell-Upload.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 2

School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. School Attendance Monitoring System 1.0 tiene Cross-Site Request Forgery (CSRF) mediante /user/user/edit.php. School Attendance Monitoring System version 1.0 suffers from a cross site request forgery vulnerability. • https://www.exploit-db.com/exploits/45725 http://packetstormsecurity.com/files/150008/School-Attendance-Monitoring-System-1.0-Cross-Site-Request-Forgery.html • CWE-352: Cross-Site Request Forgery (CSRF) •