Simple Document Management System
Products
2- 8 CVEs
- 2 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43484 | Cri | 0.64 | 9.8 | 0.03 | Mar 31, 2022 | A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request. | ||
| CVE-2021-45253 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2021 | The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The… | ||
| CVE-2022-42249 | Hig | 0.47 | 7.2 | 0.01 | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=. | ||
| CVE-2022-28063 | Med | 0.32 | 4.9 | 0.01 | Apr 4, 2022 | Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products. | ||
| CVE-2025-63442 | Med | 0.30 | 4.6 | 0.00 | Nov 3, 2025 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser | ||
| CVE-2024-40443 | Med | 0.28 | 4.3 | 0.01 | Nov 13, 2024 | SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php | ||
| CVE-2010-4986 | 0.03 | — | 0.01 | Nov 1, 2011 | SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter. | |||
| CVE-2008-6236 | 0.03 | — | 0.01 | Feb 21, 2009 | SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are… | |||
| CVE-2008-6220 | 0.03 | — | 0.01 | Feb 20, 2009 | SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter. |
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.
- risk 0.64cvss 9.8epss 0.01
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
- risk 0.32cvss 4.9epss 0.01
Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
- risk 0.30cvss 4.6epss 0.00
Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser
- risk 0.28cvss 4.3epss 0.01
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
- CVE-2010-4986Nov 1, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
- CVE-2008-6236Feb 21, 2009risk 0.03cvss —epss 0.01
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are…
- CVE-2008-6220Feb 20, 2009risk 0.03cvss —epss 0.01
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.