ZeroHour

Vulnerabilities

30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-44137
SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.

SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.

NVD description · AI analysis pending
7.2<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-4726
A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0.

A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-216739.

NVD description · AI analysis pending
9.8<1%
  • sanitization management system project sanitization management system
CVE-2022-44393
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.

NVD description · AI analysis pending
7.2<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-44348
+3 in the same advisory: …44347 …44345 …44277
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.

NVD description · AI analysis pending
7.2<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-44151
+4 in the same advisory: …44096 …44295 …44294 …44296
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-45214
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payl

A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes/Login.php.

NVD description · AI analysis pending
6.1<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-44278
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.

Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.

NVD description · AI analysis pending
7.2<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-3992
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System.

A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-213571.

NVD description · AI analysis pending
6.1<1%
  • sanitization management system project sanitization management system
CVE-2022-3942
A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic.

A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.

NVD description · AI analysis pending
6.1<1%
  • sanitization management system project sanitization management system
CVE-2022-43352
+2 in the same advisory: …43350 …43351
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.

NVD description · AI analysis pending
7.2
group max
<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-3868
A vulnerability classified as critical has been found in SourceCodester Sanitization Management System.

A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an unknown function of the file /php-sms/classes/Master.php?f=save_quote. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213012.

NVD description · AI analysis pending
9.8<1%
  • sanitization management system project sanitization management system
CVE-2022-43355
+2 in the same advisory: …43354 …43353
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service

Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.

NVD description · AI analysis pending
7.2<1% PoC
  • sanitization management system project sanitization management system
CVE-2022-3674
+2 in the same advisory: …3673 …3672
A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical.

A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier VDB-212017 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8
group max
<1%
  • sanitization management system project sanitization management system
CVE-2022-3519
+1 in the same advisory: …3518
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0.

A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Quote Requests Tab. The manipulation of the argument Manage Remarks leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-211015.

NVD description · AI analysis pending
6.1
group max
<1%
  • sanitization management system project sanitization management system
CVE-2022-3504
+1 in the same advisory: …3505
A vulnerability was found in SourceCodester Sanitization Management System and classified as critical.

A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210839.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • sanitization management system project sanitization management system