Prison Management System是Carlo Montero个人开发者的一个监狱管理系统。 Prison Management System 1.0 版本存在代码问题漏洞,该漏洞源于 /Admin/edit-photo.php of the component Avatar Handler 文件的 avatar 参数可以进行不受限制的文件上传。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Prison Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-3416 | 6.3 MEDIUM | SourceCodester Online Courseware editt.php sql injection |
| CVE-2024-3417 | 6.3 MEDIUM | SourceCodester Online Courseware saveeditt.php sql injection |
| CVE-2024-3418 | 6.3 MEDIUM | SourceCodester Online Courseware deactivateteach.php sql injection |
| CVE-2024-3419 | 6.3 MEDIUM | SourceCodester Online Courseware edit.php sql injection |
| CVE-2024-3420 | 6.3 MEDIUM | SourceCodester Online Courseware saveedit.php sql injection |
| CVE-2024-3421 | 6.3 MEDIUM | SourceCodester Online Courseware deactivatestud.php sql injection |
| CVE-2024-3422 | 6.3 MEDIUM | SourceCodester Online Courseware activatestud.php sql injection |
| CVE-2024-3423 | 6.3 MEDIUM | SourceCodester Online Courseware activateteach.php sql injection |
| CVE-2024-3424 | 6.3 MEDIUM | SourceCodester Online Courseware listscore.php sql injection |
| CVE-2024-3425 | 6.3 MEDIUM | SourceCodester Online Courseware activateall.php sql injection |
| CVE-2024-3426 | 3.5 LOW | SourceCodester Online Courseware editt.php cross site scripting |
| CVE-2024-3427 | 3.5 LOW | SourceCodester Online Courseware addq.php cross site scripting |
| CVE-2024-3428 | 3.5 LOW | SourceCodester Online Courseware edit.php cross site scripting |
No comments yet