oretnom23 kayıtları
oretnom23 üreticisine ait 761 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %0,3
- Pre-auth RCE
- 46
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')376
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')166
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')76
- CWE-434 Unrestricted Upload of File with Dangerous Type25
- CWE-707 Improper Neutralization18
- CWE-352 Cross-Site Request Forgery (CSRF)17
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
761 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2022-40471Silahlaştırılmış | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploaoretnom23 · clinic\'s patient management system · CWE-434 | Kritik9,8 | — | %21,8 | 31 Eki 2022 |
44Planlayın | CVE-2024-0264İstismar yok | SourceCodester Clinic Queuing System LoginRegistration.php authorizationoretnom23 · clinic queuing system · CWE-639 | Kritik9,8 | — | %18,2 | 7 Oca 2024 |
42Planlayın | CVE-2021-42580Kavram kanıtı | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and auoretnom23 · online learning system · CWE-89 | Kritik9,8 | — | %10,0 | 15 Kas 2021 |
41Planlayın | CVE-2024-0265İstismar yok | SourceCodester Clinic Queuing System GET Parameter index.php file inclusionoretnom23 · clinic queuing system · CWE-73 | Yüksek8,8 | — | %20,9 | 7 Oca 2024 |
41Planlayın | CVE-2021-44653Kavram kanıtı | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.oretnom23 · online magazine management system · CWE-89 | Kritik9,8 | — | %6,0 | 15 Ara 2021 |
40Planlayın | CVE-2021-43140Kavram kanıtı | SQL Injection vulnerability exists in Sourcecodester.oretnom23 · simple subscription website · CWE-89 | Kritik9,8 | — | %4,7 | 3 Kas 2021 |
40Planlayın | CVE-2023-1826Kavram kanıtı | SourceCodester Online Computer and Laptop Store index.php unrestricted uploadoretnom23 · online computer and laptop store · CWE-434 | Kritik9,8 | — | %4,4 | 4 Nis 2023 |
40Planlayın | CVE-2023-33592Kavram kanıtı | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=systeoretnom23 · lost and found information system · CWE-89 | Kritik9,8 | — | %3,8 | 28 Haz 2023 |
40Planlayın | CVE-2023-34581Kavram kanıtı | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&oretnom23 · service provider management system · CWE-89 | Kritik9,8 | — | %3,3 | 12 Haz 2023 |
40Planlayın | CVE-2021-40247İstismar yok | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL coretnom23 · budget and expense tracker system · CWE-89 | Kritik9,8 | — | %2,6 | 21 Oca 2022 |
40Planlayın | CVE-2022-26645İstismar yok | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted Poretnom23 · banking system · CWE-434 | Kritik9,8 | — | %2,5 | 30 Mar 2022 |
40Planlayın | CVE-2021-41644Kavram kanıtı | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that byoretnom23 · online food ordering system · CWE-434 | Kritik9,8 | — | %2,5 | 29 Eki 2021 |
40Planlayın | CVE-2024-34833Kavram kanıtı | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.oretnom23 · payroll management system · CWE-434 | Kritik9,8 | — | %2,0 | 17 Haz 2024 |
39İzleyin | CVE-2022-26283İstismar yok | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.oretnom23 · simple subscription website · CWE-89 | Kritik9,8 | — | %1,6 | 21 Mar 2022 |
39İzleyin | CVE-2021-46200İstismar yok | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.oretnom23 · simple music cloud community system · CWE-89 | Kritik9,8 | — | %1,6 | 21 Oca 2022 |
39İzleyin | CVE-2021-46309İstismar yok | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.oretnom23 · employee and visitor gate pass logging system · CWE-89 | Kritik9,8 | — | %1,6 | 21 Oca 2022 |
39İzleyin | CVE-2023-31857İstismar yok | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.oretnom23 · online computer and laptop store · CWE-434 | Kritik9,8 | — | %1,5 | 16 May 2023 |
39İzleyin | CVE-2022-36270İstismar yok | Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.oretnom23 · clinic\'s patient management system | Kritik9,8 | — | %1,4 | 10 Ağu 2022 |
39İzleyin | CVE-2023-43457İstismar yok | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/adminoretnom23 · service provider management system · CWE-269 | Kritik9,8 | — | %1,4 | 25 Eyl 2023 |
39İzleyin | CVE-2024-3376İstismar yok | SourceCodester Computer Laboratory Management System config.php redirectoretnom23 · computer laboratory management system · CWE-698 | Kritik9,8 | — | %1,3 | 6 Nis 2024 |
39İzleyin | CVE-2023-31704Kavram kanıtı | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privoretnom23 · online computer and laptop store · CWE-863 | Kritik9,8 | — | %1,3 | 13 Tem 2023 |
39İzleyin | CVE-2022-27304İstismar yok | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.oretnom23 · student grading system · CWE-89 | Kritik9,8 | — | %1,3 | 5 Nis 2022 |
39İzleyin | CVE-2023-38965İstismar yok | Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.oretnom23 · lost and found information system · CWE-639 | Kritik9,8 | — | %1,3 | 3 Kas 2023 |
39İzleyin | CVE-2022-29650İstismar yok | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/foodoretnom23 · online food ordering system · CWE-89 | Kritik9,8 | — | %1,3 | 25 May 2022 |
39İzleyin | CVE-2021-41659İstismar yok | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the useoretnom23 · banking system · CWE-89 | Kritik9,8 | — | %1,3 | 24 Oca 2022 |
- CVE-2022-4047146Planlayın
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploa
KritikCVSS 9,8SilahlaştırılmışEPSS %22oretnom23 · clinic\'s patient management system31 Eki 2022
- CVE-2024-026444Planlayın
SourceCodester Clinic Queuing System LoginRegistration.php authorization
KritikCVSS 9,8İstismar yokEPSS %18oretnom23 · clinic queuing system7 Oca 2024
- CVE-2021-4258042Planlayın
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and au
KritikCVSS 9,8Kavram kanıtıEPSS %10oretnom23 · online learning system15 Kas 2021
- CVE-2024-026541Planlayın
SourceCodester Clinic Queuing System GET Parameter index.php file inclusion
YüksekCVSS 8,8İstismar yokEPSS %21oretnom23 · clinic queuing system7 Oca 2024
- CVE-2021-4465341Planlayın
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.
KritikCVSS 9,8Kavram kanıtıEPSS %6oretnom23 · online magazine management system15 Ara 2021
- CVE-2021-4314040Planlayın
SQL Injection vulnerability exists in Sourcecodester.
KritikCVSS 9,8Kavram kanıtıEPSS %5oretnom23 · simple subscription website3 Kas 2021
- CVE-2023-182640Planlayın
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
KritikCVSS 9,8Kavram kanıtıEPSS %4oretnom23 · online computer and laptop store4 Nis 2023
- CVE-2023-3359240Planlayın
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=syste
KritikCVSS 9,8Kavram kanıtıEPSS %4oretnom23 · lost and found information system28 Haz 2023
- CVE-2023-3458140Planlayın
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&
KritikCVSS 9,8Kavram kanıtıEPSS %3oretnom23 · service provider management system12 Haz 2023
- CVE-2021-4024740Planlayın
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL c
KritikCVSS 9,8İstismar yokEPSS %3oretnom23 · budget and expense tracker system21 Oca 2022
- CVE-2022-2664540Planlayın
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted P
KritikCVSS 9,8İstismar yokEPSS %3oretnom23 · banking system30 Mar 2022
- CVE-2021-4164440Planlayın
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that by
KritikCVSS 9,8Kavram kanıtıEPSS %2oretnom23 · online food ordering system29 Eki 2021
- CVE-2024-3483340Planlayın
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.
KritikCVSS 9,8Kavram kanıtıEPSS %2oretnom23 · payroll management system17 Haz 2024
- CVE-2022-2628339İzleyin
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.
KritikCVSS 9,8İstismar yokEPSS %2oretnom23 · simple subscription website21 Mar 2022
- CVE-2021-4620039İzleyin
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
KritikCVSS 9,8İstismar yokEPSS %2oretnom23 · simple music cloud community system21 Oca 2022
- CVE-2021-4630939İzleyin
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
KritikCVSS 9,8İstismar yokEPSS %2oretnom23 · employee and visitor gate pass logging system21 Oca 2022
- CVE-2023-3185739İzleyin
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.
KritikCVSS 9,8İstismar yokEPSS %2oretnom23 · online computer and laptop store16 May 2023
- CVE-2022-3627039İzleyin
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · clinic\'s patient management system10 Ağu 2022
- CVE-2023-4345739İzleyin
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · service provider management system25 Eyl 2023
- CVE-2024-337639İzleyin
SourceCodester Computer Laboratory Management System config.php redirect
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · computer laboratory management system6 Nis 2024
- CVE-2023-3170439İzleyin
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate priv
KritikCVSS 9,8Kavram kanıtıEPSS %1oretnom23 · online computer and laptop store13 Tem 2023
- CVE-2022-2730439İzleyin
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · student grading system5 Nis 2022
- CVE-2023-3896539İzleyin
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · lost and found information system3 Kas 2023
- CVE-2022-2965039İzleyin
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · online food ordering system25 May 2022
- CVE-2021-4165939İzleyin
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the use
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · banking system24 Oca 2022