CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
Library Management System 1.0 has SQL Injection via the "Search for Books" screen.
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
