2 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request. /view/friend_profile.php en Ingenious School Management System 2.3.0 es vulnerable a una inyección SQL basada en booleanos y en tiempo en el parámetro "friend_index" de una petición GET. • https://www.exploit-db.com/exploits/43108 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. my_profile.php en Ingenious School Management System 2.3.0 permite que un estudiante o profesor suba un archivo arbitrario. Ingenious School Management System version 2.3.0 suffers from a remote file upload vulnerability. • https://www.exploit-db.com/exploits/43102 https://packetstormsecurity.com/files/144431/Ingenious-School-Management-System-2.3.0-Arbitrary-File-Upload.html • CWE-434: Unrestricted Upload of File with Dangerous Type •