VYPR
Vendor

Simple College Website Project

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2022-40089CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

  • CVE-2022-40087CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-26232CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.

  • CVE-2021-44593HigJan 21, 2022
    risk 0.53cvss 8.1epss 0.04

    Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

  • CVE-2022-40088MedSep 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…