CVE-2022-40878 Exam Reviewer Management System 1.0 allows an attacker to upload a web-shell php file and achieve RCE.
An attacker can do this by setting up a fake facebook account or by manipulating the system to access the system’s data. By uploading
CVE-2022-40877 Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
The id parameter is usually used to select a specific record when creating a new post. If an attacker inputs ‘;’ or other malicious characters into
CVE-2022-40089 An RFI vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code.
When a user browses to malicious or third-party web-based file or enters the directory structure (i.e., /directory/filename) that is under the
CVE-2022-35022 An OTFC commit contained a segmentation violation.
This was resolved by changing the size of the data field from 39 bytes to 31 bytes.
An additional resolution was discovered through fuzzing. Several
CVE-2022-40932 - How Hackers Can Exploit Zoo Management System v1. with Arbitrary File Upload
Disclaimer: The following article is for educational purposes only. Do not use this information for unauthorized hacking. Always have permission before testing systems.
What is
Episode
00:00:00
00:00:00