CVE-2022-36572 Sinsiu Enterprise Website System v1.1.1.0 had an RCE vulnerability that was discovered via the /upload/admin.php?/deal/ component.
The component upload/admin.php?/deal/ allows users to upload files to the system. This can be leveraged to upload arbitrary code to the system.
CVE-2022-36706 The Stock Management System v1.0 had a SQL injection vulnerability.
It appears that the application had not enabled the id_ parameter, which allowed attackers to inject script code or SQL commands that were executed when
CVE-2022-36708 Library Management System v1.0 had an SQL injection vulnerability where the Id parameter was vulnerable.
A hacker can inject arbitrary SQL queries that will be executed if a user visits a maliciously crafted URL or if they try to edit
CVE-2022-3014 An issue was found in SourceCodester Simple Task Managing System. Manipulating the argument student_add leads to cross site scripting. The vulnerability can be exploited remotely.
If there is a task in the system where the student_id argument is mandatory and there is no input validation, it could be exploited
CVE-2022-36719 The Ok parameter of the Library Management System v1.0 was found to be vulnerable to SQL injection.
An attacker can inject arbitrary SQL queries that enable SQL injection and obtain access to internal database structures. Any system that uses this software, especially
Episode
00:00:00
00:00:00