Vulnerabilities > Schools Alert Management Script Project > Schools Alert Management Script > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-06-08 CVE-2018-12051 Unrestricted Upload of File with Dangerous Type vulnerability in Schools Alert Management Script Project Schools Alert Management Script
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.
network
low complexity
schools-alert-management-script-project CWE-434
critical
9.8
2018-06-08 CVE-2018-12052 SQL Injection vulnerability in Schools Alert Management Script Project Schools Alert Management Script
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
network
low complexity
schools-alert-management-script-project CWE-89
critical
9.8
2018-06-08 CVE-2018-12055 SQL Injection vulnerability in Schools Alert Management Script Project Schools Alert Management Script
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.
network
low complexity
schools-alert-management-script-project CWE-89
critical
9.8
2018-02-23 CVE-2018-6859 SQL Injection vulnerability in Schools Alert Management Script Project Schools Alert Management Script 2.0.2
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.
network
low complexity
schools-alert-management-script-project CWE-89
critical
9.8