Monthly Archive: May 2022

CVE-2022-29655

An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. Date published : 2022-05-11 https://hackmd.io/HcH7QdEdRu67yfTJsKKFKA

CVE-2022-29613

Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a...

CVE-2022-29596

MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal. Date published : 2022-05-11 https://github.com/haxpunk1337/Microstrategy-Poc/blob/main/poc

CVE-2022-29318

An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. Date published : 2022-05-11 https://hackmd.io/ITi4yd2-RgmDZh8FW-KTlA

CVE-2022-29317

Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php. Date published : 2022-05-11 https://hackmd.io/@taidh/r1FCJ1ME5

CVE-2022-29316

Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch. Date published : 2022-05-11 https://hackmd.io/@taidh/SyioJJGEq

CVE-2022-29009

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. Date published : 2022-05-11 https://www.exploit-db.com/exploits/50355

CVE-2022-29008

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information. Date published : 2022-05-11 https://www.exploit-db.com/exploits/50263

CVE-2022-29007

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication. Date published : 2022-05-11 https://www.exploit-db.com/exploits/50365