Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jnoj jiangnan online judge 0.8.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2019-17538
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
Jnoj Jiangnan Online Judge 0.8.0
6.1
CVSSv3
CVE-2019-17493
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.
Jnoj Jiangnan Online Judge 0.8.0
6.1
CVSSv3
CVE-2019-17489
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create.
Jnoj Jiangnan Online Judge 0.8.0
8.8
CVSSv3
CVE-2019-17490
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content type) to the web/polygon/problem/tests URI.
Jnoj Jiangnan Online Judge 0.8.0
6.1
CVSSv3
CVE-2019-17491
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update.
Jnoj Jiangnan Online Judge 0.8.0
7.5
CVSSv3
CVE-2019-17537
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
Jnoj Jiangnan Online Judge 0.8.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started