RSS   Vulnerabilities for 'The school manage system'   RSS

2020-04-15
 
CVE-2020-10507

CWE-434
 

 
The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that would allow attackers to gain access in the hosting machine.

 
 
CVE-2020-10506

CWE-22
 

 
The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.

 
 
CVE-2020-10505

CWE-89
 

 
The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, an attacker can use a union based injection query string to get databases schema and username/password.

 


Copyright 2024, cxsecurity.com

 

Back to Top