Skip to content
Noroxi

oretnom23 records

761 published records for vendor oretnom23.

All records

761 records
  • Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploa

    CriticalCVSS 9.8WeaponizedEPSS 22%

    oretnom23 · clinic\'s patient management systemOct 31, 2022

  • SourceCodester Clinic Queuing System LoginRegistration.php authorization

    CriticalCVSS 9.8No exploitEPSS 18%

    oretnom23 · clinic queuing systemJan 7, 2024

  • Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and au

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    oretnom23 · online learning systemNov 15, 2021

  • SourceCodester Clinic Queuing System GET Parameter index.php file inclusion

    HighCVSS 8.8No exploitEPSS 21%

    oretnom23 · clinic queuing systemJan 7, 2024

  • Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    oretnom23 · online magazine management systemDec 15, 2021

  • SQL Injection vulnerability exists in Sourcecodester.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    oretnom23 · simple subscription websiteNov 3, 2021

  • SourceCodester Online Computer and Laptop Store index.php unrestricted upload

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    oretnom23 · online computer and laptop storeApr 4, 2023

  • Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=syste

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    oretnom23 · lost and found information systemJun 28, 2023

  • Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    oretnom23 · service provider management systemJun 12, 2023

  • SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL c

    CriticalCVSS 9.8No exploitEPSS 3%

    oretnom23 · budget and expense tracker systemJan 21, 2022

  • A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted P

    CriticalCVSS 9.8No exploitEPSS 3%

    oretnom23 · banking systemMar 30, 2022

  • Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that by

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    oretnom23 · online food ordering systemOct 29, 2021

  • Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    oretnom23 · payroll management systemJun 17, 2024

  • Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.

    CriticalCVSS 9.8No exploitEPSS 2%

    oretnom23 · simple subscription websiteMar 21, 2022

  • An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    oretnom23 · simple music cloud community systemJan 21, 2022

  • An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    oretnom23 · employee and visitor gate pass logging systemJan 21, 2022

  • Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.

    CriticalCVSS 9.8No exploitEPSS 2%

    oretnom23 · online computer and laptop storeMay 16, 2023

  • Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · clinic\'s patient management systemAug 10, 2022

  • An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · service provider management systemSep 25, 2023

  • CVE-2024-3376
    39Monitor

    SourceCodester Computer Laboratory Management System config.php redirect

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · computer laboratory management systemApr 6, 2024

  • Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate priv

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    oretnom23 · online computer and laptop storeJul 13, 2023

  • Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · student grading systemApr 5, 2022

  • Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · lost and found information systemNov 3, 2023

  • Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · online food ordering systemMay 25, 2022

  • SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the use

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · banking systemJan 24, 2022