SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
References
Configurations
Configuration 1 (hide)
|
History
19 Sep 2023, 21:24
Type | Values Removed | Values Added |
---|---|---|
First Time |
Exam Form Submission In Php With Source Code Project
Exam Form Submission In Php With Source Code Project exam Form Submission In Php With Source Code |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-89 | |
References | (MISC) https://upbeat-washer-def.notion.site/Exam-Form-Submission-In-PHP-SQL-Injection-in-index-php-bd71962db712459488019d531ab2f6f2?pvs=4 - Exploit | |
CPE | cpe:2.3:a:exam_form_submission_in_php_with_source_code_project:exam_form_submission_in_php_with_source_code:1.0:*:*:*:*:*:*:* |
18 Sep 2023, 13:26
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-18 12:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-42359
Mitre link : CVE-2023-42359
CVE.ORG link : CVE-2023-42359
JSON object : View
Products Affected
exam_form_submission_in_php_with_source_code_project
- exam_form_submission_in_php_with_source_code
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')