CVE-2024-7278 – itsourcecode Alton Management System team_save.php sql injection
https://notcve.org/view.php?id=CVE-2024-7278
A vulnerability was found in itsourcecode Alton Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_save.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/DeepMountains/Mirage/blob/main/CVE8-6.md https://vuldb.com/?ctiid.273147 https://vuldb.com/?id.273147 https://vuldb.com/?submit.381096 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7277 – itsourcecode Alton Management System Add a Menu menu.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-7277
A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/menu.php of the component Add a Menu. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/DeepMountains/Mirage/blob/main/CVE8-5.md https://vuldb.com/?ctiid.273146 https://vuldb.com/?id.273146 https://vuldb.com/?submit.381095 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-7276 – itsourcecode Alton Management System member_save.php sql injection
https://notcve.org/view.php?id=CVE-2024-7276
A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/member_save.php. The manipulation of the argument last/first leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/DeepMountains/Mirage/blob/main/CVE8-4.md https://vuldb.com/?ctiid.273145 https://vuldb.com/?id.273145 https://vuldb.com/?submit.381094 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7275 – itsourcecode Alton Management System category_save.php sql injection
https://notcve.org/view.php?id=CVE-2024-7275
A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an unknown function of the file /admin/category_save.php. The manipulation of the argument category leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/DeepMountains/Mirage/blob/main/CVE8-3.md https://vuldb.com/?ctiid.273144 https://vuldb.com/?id.273144 https://vuldb.com/?submit.381093 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-7274 – itsourcecode Alton Management System reservation_status.php sql injection
https://notcve.org/view.php?id=CVE-2024-7274
A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issue affects some unknown processing of the file /reservation_status.php. The manipulation of the argument rcode leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/DeepMountains/Mirage/blob/main/CVE8-2.md https://vuldb.com/?ctiid.273143 https://vuldb.com/?id.273143 https://vuldb.com/?submit.381091 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •