geo-chen/code-projects

geo-chen/code-projects

Releases0
A hands-on repository for my students to explore CVE assignments through bug-hunting on code-projects.org.

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Page. Performing a manipulation of the argument User results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

6.3 MEDIUM6.5 MEDIUM

A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admin_pic.php. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

3.5 LOW4 MEDIUM

A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.