ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36118
Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the

Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2023-33569
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.

NVD description · AI analysis pending
7.21% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2023-2962
A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0.

A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230150 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2023-33440
+1 in the same advisory: …33439
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

NVD description · AI analysis pending
7.215% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2023-31845
+3 in the same advisory: …31844 …31843 …31842
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

NVD description · AI analysis pending
7.2<1% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2023-2366
+4 in the same advisory: …2365 …2368 …2367 …2369
A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical.

A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajax.php?action=delete_class. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227642 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • faculty evaluation system project faculty evaluation system
CVE-2018-18758
+1 in the same advisory: …18757
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.

Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.

NVD description · AI analysis pending
9.82% PoC
  • open faculty evaluation system project open faculty evaluation system