Записи oretnom23
761 опубликованных записей вендора oretnom23.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 0,3 %
- Pre-auth RCE
- 46
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')376
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')166
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')76
- CWE-434 Unrestricted Upload of File with Dangerous Type25
- CWE-707 Improper Neutralization18
- CWE-352 Cross-Site Request Forgery (CSRF)17
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
761 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2022-40471Готовый эксплойт | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploaoretnom23 · clinic\'s patient management system · CWE-434 | Критическая9,8 | — | 21,8 % | 31 окт. 2022 г. |
44В плане | CVE-2024-0264Эксплойта нет | SourceCodester Clinic Queuing System LoginRegistration.php authorizationoretnom23 · clinic queuing system · CWE-639 | Критическая9,8 | — | 18,2 % | 7 янв. 2024 г. |
42В плане | CVE-2021-42580Proof of concept | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and auoretnom23 · online learning system · CWE-89 | Критическая9,8 | — | 10,0 % | 15 нояб. 2021 г. |
41В плане | CVE-2024-0265Эксплойта нет | SourceCodester Clinic Queuing System GET Parameter index.php file inclusionoretnom23 · clinic queuing system · CWE-73 | Высокая8,8 | — | 20,9 % | 7 янв. 2024 г. |
41В плане | CVE-2021-44653Proof of concept | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.oretnom23 · online magazine management system · CWE-89 | Критическая9,8 | — | 6,0 % | 15 дек. 2021 г. |
40В плане | CVE-2021-43140Proof of concept | SQL Injection vulnerability exists in Sourcecodester.oretnom23 · simple subscription website · CWE-89 | Критическая9,8 | — | 4,7 % | 3 нояб. 2021 г. |
40В плане | CVE-2023-1826Proof of concept | SourceCodester Online Computer and Laptop Store index.php unrestricted uploadoretnom23 · online computer and laptop store · CWE-434 | Критическая9,8 | — | 4,4 % | 4 апр. 2023 г. |
40В плане | CVE-2023-33592Proof of concept | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=systeoretnom23 · lost and found information system · CWE-89 | Критическая9,8 | — | 3,8 % | 28 июн. 2023 г. |
40В плане | CVE-2023-34581Proof of concept | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&oretnom23 · service provider management system · CWE-89 | Критическая9,8 | — | 3,3 % | 12 июн. 2023 г. |
40В плане | CVE-2021-40247Эксплойта нет | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL coretnom23 · budget and expense tracker system · CWE-89 | Критическая9,8 | — | 2,6 % | 21 янв. 2022 г. |
40В плане | CVE-2022-26645Эксплойта нет | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted Poretnom23 · banking system · CWE-434 | Критическая9,8 | — | 2,5 % | 30 мар. 2022 г. |
40В плане | CVE-2021-41644Proof of concept | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that byoretnom23 · online food ordering system · CWE-434 | Критическая9,8 | — | 2,5 % | 29 окт. 2021 г. |
40В плане | CVE-2024-34833Proof of concept | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.oretnom23 · payroll management system · CWE-434 | Критическая9,8 | — | 2,0 % | 17 июн. 2024 г. |
39Наблюдать | CVE-2022-26283Эксплойта нет | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.oretnom23 · simple subscription website · CWE-89 | Критическая9,8 | — | 1,6 % | 21 мар. 2022 г. |
39Наблюдать | CVE-2021-46200Эксплойта нет | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.oretnom23 · simple music cloud community system · CWE-89 | Критическая9,8 | — | 1,6 % | 21 янв. 2022 г. |
39Наблюдать | CVE-2021-46309Эксплойта нет | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.oretnom23 · employee and visitor gate pass logging system · CWE-89 | Критическая9,8 | — | 1,6 % | 21 янв. 2022 г. |
39Наблюдать | CVE-2023-31857Эксплойта нет | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.oretnom23 · online computer and laptop store · CWE-434 | Критическая9,8 | — | 1,5 % | 16 мая 2023 г. |
39Наблюдать | CVE-2022-36270Эксплойта нет | Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.oretnom23 · clinic\'s patient management system | Критическая9,8 | — | 1,4 % | 10 авг. 2022 г. |
39Наблюдать | CVE-2023-43457Эксплойта нет | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/adminoretnom23 · service provider management system · CWE-269 | Критическая9,8 | — | 1,4 % | 25 сент. 2023 г. |
39Наблюдать | CVE-2024-3376Эксплойта нет | SourceCodester Computer Laboratory Management System config.php redirectoretnom23 · computer laboratory management system · CWE-698 | Критическая9,8 | — | 1,3 % | 6 апр. 2024 г. |
39Наблюдать | CVE-2023-31704Proof of concept | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privoretnom23 · online computer and laptop store · CWE-863 | Критическая9,8 | — | 1,3 % | 13 июл. 2023 г. |
39Наблюдать | CVE-2022-27304Эксплойта нет | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.oretnom23 · student grading system · CWE-89 | Критическая9,8 | — | 1,3 % | 5 апр. 2022 г. |
39Наблюдать | CVE-2023-38965Эксплойта нет | Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.oretnom23 · lost and found information system · CWE-639 | Критическая9,8 | — | 1,3 % | 3 нояб. 2023 г. |
39Наблюдать | CVE-2022-29650Эксплойта нет | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/foodoretnom23 · online food ordering system · CWE-89 | Критическая9,8 | — | 1,3 % | 25 мая 2022 г. |
39Наблюдать | CVE-2021-41659Эксплойта нет | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the useoretnom23 · banking system · CWE-89 | Критическая9,8 | — | 1,3 % | 24 янв. 2022 г. |
- CVE-2022-4047146В плане
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploa
КритическаяCVSS 9,8Готовый эксплойтEPSS 22 %oretnom23 · clinic\'s patient management system31 окт. 2022 г.
- CVE-2024-026444В плане
SourceCodester Clinic Queuing System LoginRegistration.php authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %oretnom23 · clinic queuing system7 янв. 2024 г.
- CVE-2021-4258042В плане
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and au
КритическаяCVSS 9,8Proof of conceptEPSS 10 %oretnom23 · online learning system15 нояб. 2021 г.
- CVE-2024-026541В плане
SourceCodester Clinic Queuing System GET Parameter index.php file inclusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %oretnom23 · clinic queuing system7 янв. 2024 г.
- CVE-2021-4465341В плане
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 6 %oretnom23 · online magazine management system15 дек. 2021 г.
- CVE-2021-4314040В плане
SQL Injection vulnerability exists in Sourcecodester.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %oretnom23 · simple subscription website3 нояб. 2021 г.
- CVE-2023-182640В плане
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
КритическаяCVSS 9,8Proof of conceptEPSS 4 %oretnom23 · online computer and laptop store4 апр. 2023 г.
- CVE-2023-3359240В плане
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=syste
КритическаяCVSS 9,8Proof of conceptEPSS 4 %oretnom23 · lost and found information system28 июн. 2023 г.
- CVE-2023-3458140В плане
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&
КритическаяCVSS 9,8Proof of conceptEPSS 3 %oretnom23 · service provider management system12 июн. 2023 г.
- CVE-2021-4024740В плане
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL c
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %oretnom23 · budget and expense tracker system21 янв. 2022 г.
- CVE-2022-2664540В плане
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted P
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %oretnom23 · banking system30 мар. 2022 г.
- CVE-2021-4164440В плане
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that by
КритическаяCVSS 9,8Proof of conceptEPSS 2 %oretnom23 · online food ordering system29 окт. 2021 г.
- CVE-2024-3483340В плане
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %oretnom23 · payroll management system17 июн. 2024 г.
- CVE-2022-2628339Наблюдать
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %oretnom23 · simple subscription website21 мар. 2022 г.
- CVE-2021-4620039Наблюдать
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %oretnom23 · simple music cloud community system21 янв. 2022 г.
- CVE-2021-4630939Наблюдать
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %oretnom23 · employee and visitor gate pass logging system21 янв. 2022 г.
- CVE-2023-3185739Наблюдать
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %oretnom23 · online computer and laptop store16 мая 2023 г.
- CVE-2022-3627039Наблюдать
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · clinic\'s patient management system10 авг. 2022 г.
- CVE-2023-4345739Наблюдать
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · service provider management system25 сент. 2023 г.
- CVE-2024-337639Наблюдать
SourceCodester Computer Laboratory Management System config.php redirect
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · computer laboratory management system6 апр. 2024 г.
- CVE-2023-3170439Наблюдать
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate priv
КритическаяCVSS 9,8Proof of conceptEPSS 1 %oretnom23 · online computer and laptop store13 июл. 2023 г.
- CVE-2022-2730439Наблюдать
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · student grading system5 апр. 2022 г.
- CVE-2023-3896539Наблюдать
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · lost and found information system3 нояб. 2023 г.
- CVE-2022-2965039Наблюдать
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · online food ordering system25 мая 2022 г.
- CVE-2021-4165939Наблюдать
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the use
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · banking system24 янв. 2022 г.