Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32394 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3
CVE-2022-32396 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4
CVE-2022-32395 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4
CVE-2022-32397 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4
CVE-2022-32398 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4
CVE-2022-32399 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4
CVE-2022-32400 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 7.2 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.
CVE-2022-32401 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4
CVE-2022-32402 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4
CVE-2022-32403 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4
CVE-2022-32404 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3
CVE-2022-32405 1 Prison Management System Project 1 Prison Management System 2022-06-29 6.5 MEDIUM 8.8 HIGH
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4
CVE-2021-40956 1 Laiketui 1 Laiketui 2022-06-29 5.0 MEDIUM 7.5 HIGH
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
CVE-2021-40955 1 Laiketui 1 Laiketui 2022-06-29 6.5 MEDIUM 7.2 HIGH
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
CVE-2022-33114 1 Jflyfox 1 Jfinal Cms 2022-06-29 6.5 MEDIUM 7.2 HIGH
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
CVE-2022-33097 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.
CVE-2022-33095 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
CVE-2022-33096 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
CVE-2022-33093 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
CVE-2022-33094 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
CVE-2022-33092 1 74cms 1 74cmsse 2022-06-29 5.0 MEDIUM 7.5 HIGH
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
CVE-2022-33048 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2022-06-28 6.5 MEDIUM 7.2 HIGH
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
CVE-2022-33049 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2022-06-28 6.5 MEDIUM 7.2 HIGH
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
CVE-2022-33056 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2022-06-28 6.5 MEDIUM 7.2 HIGH
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.
CVE-2022-33055 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2022-06-28 6.5 MEDIUM 7.2 HIGH
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
CVE-2019-12359 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 7.2 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12358 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 8.8 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
CVE-2019-12357 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 7.2 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12355 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 8.8 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
CVE-2019-12356 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 8.8 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
CVE-2019-12354 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 7.2 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12353 1 Zzcms 1 Zzcms 2022-06-28 6.5 MEDIUM 7.2 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
CVE-2019-12352 1 Zzcms 1 Zzcms 2022-06-27 6.5 MEDIUM 8.8 HIGH
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
CVE-2020-35597 1 Victor Cms Project 1 Victor Cms 2022-06-27 6.5 MEDIUM 8.8 HIGH
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
CVE-2019-5122 1 Youphptube 1 Youphptube 2022-06-27 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.
CVE-2019-5150 1 Youphptube 1 Youphptube 2022-06-27 6.8 MEDIUM 8.1 HIGH
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2019-5123 1 Youphptube 1 Youphptube 2022-06-27 6.5 MEDIUM 8.8 HIGH
Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.
CVE-2022-23169 1 Amodat 1 Mobile Application Gateway 2022-06-27 6.5 MEDIUM 7.2 HIGH
attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
CVE-2022-31908 1 Student Registration And Fee Payment System Project 1 Student Registration And Fee Payment System 2022-06-27 6.5 MEDIUM 7.2 HIGH
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
CVE-2022-31911 1 Online Discussion Forum Site Project 1 Online Discussion Forum Site 2022-06-27 6.5 MEDIUM 7.2 HIGH
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
CVE-2022-31912 1 Online Tutor Portal Site Project 1 Online Tutor Portal Site 2022-06-27 6.5 MEDIUM 7.2 HIGH
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
CVE-2022-32371 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=.
CVE-2022-32370 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=.
CVE-2022-32372 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.
CVE-2022-32373 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=.
CVE-2022-32374 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=.
CVE-2022-32368 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=.
CVE-2022-32300 1 Youdian Software 1 Youdiancms 2022-06-24 6.5 MEDIUM 8.8 HIGH
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php.
CVE-2022-32299 1 Youdian Software 1 Youdiancms 2022-06-24 6.5 MEDIUM 8.8 HIGH
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php.
CVE-2022-32302 1 Theme Park Ticketing System Project 1 Theme Park Ticketing System 2022-06-24 6.5 MEDIUM 8.8 HIGH
Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php.