5.3

CVSS4.0

CVE-2024-7171 - TOTOLINK A3600R cstecgi.cgi NTPSyncWithHost os command injection

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostTime leads to os command injection. It is possible to launch the attack remotely. The expl…

πŸ“… Published: July 28, 2024, 10:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

5.1

CVSS4.0

CVE-2024-7170 - TOTOLINK A3000RU product.ini hard-coded password

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The as…

πŸ“… Published: July 28, 2024, 10 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

6.9

CVSS4.0

CVE-2024-7169 - SourceCodester School Fees Payment System ajax.php cross-site request forgery

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the …

πŸ“… Published: July 28, 2024, 7:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7168 - SourceCodester School Fees Payment System manage_user.php sql injection

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit …

πŸ“… Published: July 28, 2024, 7 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7167 - SourceCodester School Fees Payment System manage_course.php sql injection

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /manage_course.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. T…

πŸ“… Published: July 28, 2024, 6:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7166 - SourceCodester School Fees Payment System receipt.php sql injection

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file /receipt.php. The manipulation of the argument ef_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

πŸ“… Published: July 28, 2024, 6 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7165 - SourceCodester School Fees Payment System view_payment.php sql injection

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. The manipulation of the argument ef_id leads to sql injection. The attack may be initiated remotely. The exploit has been …

πŸ“… Published: July 28, 2024, 5:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

6.9

CVSS4.0

CVE-2024-7164 - SourceCodester School Fees Payment System sql injection

A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit…

πŸ“… Published: July 28, 2024, 5 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7163 - SeaCMS index.php cross site scripting

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/index.php. The manipulation of the argument color/vid/url leads to cross site scripting. It is possible to initiate the attack remotely. The exploit ha…

πŸ“… Published: July 28, 2024, 4:31 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.

5.3

CVSS4.0

CVE-2024-7162 - SeaCMS cross site scripting

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the file js/player/dmplayer/admin/post.php?act=setting. The manipulation of the argument yzm leads to cross site scripting. The attack may be launched re…

πŸ“… Published: July 28, 2024, 4 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:50 a.m.
Total resulsts: 349182
Page 9040 of 34,919
Β« previous page Β» next page
Filters