Gas Agency Management System
by Mayurik
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36568 | Cri | 0.64 | 9.8 | 0.01 | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. | ||
| CVE-2022-37184 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2022 | The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file. | ||
| CVE-2024-36569 | Hig | 0.53 | 8.1 | 0.01 | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php. | ||
| CVE-2022-41551 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php. | ||
| CVE-2022-38877 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1. | ||
| CVE-2022-38610 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php. | ||
| CVE-2022-38606 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php. | ||
| CVE-2026-2009 | Med | 0.41 | 6.3 | 0.00 | Feb 6, 2026 | A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The… | ||
| CVE-2024-5051 | Med | 0.41 | 6.3 | 0.01 | May 17, 2024 | A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The… | ||
| CVE-2022-44279 | Med | 0.40 | 6.1 | 0.01 | Nov 29, 2022 | Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php. |
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
- risk 0.57cvss 8.8epss 0.01
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file.
- risk 0.53cvss 8.1epss 0.01
Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php.
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The…
- risk 0.41cvss 6.3epss 0.01
A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The…
- risk 0.40cvss 6.1epss 0.01
Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.