Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
project alumni project alumni vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2007-6126
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable th...
Project Alumni Project Alumni 1.0.8
Project Alumni Project Alumni
1 EDB exploit
755
VMScore
CVE-2007-6127
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and previous versions allow remote malicious users to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to...
Project Alumni Project Alumni
1 EDB exploit
755
VMScore
CVE-2007-6184
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the act parameter.
Project Alumni Project Alumni 1.0.9
1 EDB exploit
435
VMScore
CVE-2008-2117
Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote malicious users to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.
Project Alumni Project Alumni 1.0.9
1 EDB exploit
755
VMScore
CVE-2008-2118
SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Project Alumni Project Alumni 1.0.9
1 EDB exploit
668
VMScore
CVE-2020-28070
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
Alumni Management System Project Alumni Management System 1.0
312
VMScore
CVE-2020-28071
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored X...
Alumni Management System Project Alumni Management System 1.0
578
VMScore
CVE-2020-28072
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.
Alumni Management System Project Alumni Management System 1.0
668
VMScore
CVE-2021-25210
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows malicious users to execute arbitrary code, via the file upload to manage_event.php.
Alumni Management System Project Alumni Management System 1.0
668
VMScore
CVE-2021-25212
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote malicious users to execute arbitrary SQL statements, via the id parameter to manage_event.php.
Alumni Management System Project Alumni Management System 1.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »