CVE-2024-3426 – SourceCodester Online Courseware editt.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-3426
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Courseware 1.0. Affected by this issue is some unknown functionality of the file editt.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-11.md https://vuldb.com/?ctiid.259598 https://vuldb.com/?id.259598 https://vuldb.com/?submit.311605 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-3425 – SourceCodester Online Courseware activateall.php sql injection
https://notcve.org/view.php?id=CVE-2024-3425
A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. Affected by this vulnerability is an unknown functionality of the file admin/activateall.php. The manipulation of the argument selector leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-10.md https://vuldb.com/?ctiid.259597 https://vuldb.com/?id.259597 https://vuldb.com/?submit.311604 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-3424 – SourceCodester Online Courseware listscore.php sql injection
https://notcve.org/view.php?id=CVE-2024-3424
A vulnerability classified as critical has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/listscore.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-09.md https://vuldb.com/?ctiid.259596 https://vuldb.com/?id.259596 https://vuldb.com/?submit.311602 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-3423 – SourceCodester Online Courseware activateteach.php sql injection
https://notcve.org/view.php?id=CVE-2024-3423
A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. The manipulation of the argument selector leads to sql injection. The attack may be initiated remotely. • https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-08.md https://vuldb.com/?ctiid.259595 https://vuldb.com/?id.259595 https://vuldb.com/?submit.311601 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-3422 – SourceCodester Online Courseware activatestud.php sql injection
https://notcve.org/view.php?id=CVE-2024-3422
A vulnerability was found in SourceCodester Online Courseware 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/activatestud.php. The manipulation of the argument selector leads to sql injection. The attack can be initiated remotely. • https://github.com/dovankha/CVE-2024-34220 https://github.com/dovankha/CVE-2024-34221 https://github.com/dovankha/CVE-2024-34223 https://github.com/dovankha/CVE-2024-34222 https://github.com/dovankha/CVE-2024-34224 https://github.com/dovankha/CVE-2024-34226 https://github.com/dovankha/CVE-2024-34225 https://github.com/thisissuperann/Vul/blob/Online-Courseware/Online-Courseware-07.md https://vuldb.com/?ctiid.259594 https://vuldb.com/?id.259594 https://vuldb.com/ • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •