CVE-2022-41379 An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code.
This arbitrary code can be executed in a logged-in administrator user via a specially-crafted PHP file. This arbitrary code can be used to
CVE-2022-42074 The v1.0 of GED Diagnostic Lab Management System is vulnerable to SQL Injection.
A hacker can inject a SQL query to change the content of the database and steal critical information or even take over the system. A
CVE-2022-41512 An arbitrary file upload vulnerability in the /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code.
The component /php_action/editFile.php does not require any authentication to enable unauthorized users to upload files and execute code. The component should be
CVE-2022-42092 Backdrop CMS has an Unrestricted File Upload vulnerability that allows attackers to Remote Code Execution.
Unrestricted File Upload vulnerability is a serious issue, because it allows attackers to upload malicious files on the server, and execute malicious code, which can
CVE-2022-40834 B.C
An attacker can inject arbitrary SQL code into the database by setting the value of the parameter to ' or_not_like() function in system\
Episode
00:00:00
00:00:00