CVE Database
/

CVE-2014-1636

Back to search

CVE-2014-1636

Published: Jan 22, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to (1) admin_school_names.php, (2) admin_subjects.php, (3) admin_grades.php, (4) admin_terms.php, (5) admin_school_years.php, (6) admin_sgrades.php, (7) admin_media_codes_1.php, (8) admin_infraction_codes.php, (9) admin_generations.php, (10) admin_relations.php, (11) admin_titles.php, or (12) health_allergies.php in sw/.

VendorProductVersions

n/a

n/a

affected
n/a

References

101879
vdb-entry
x_refsource_OSVDB
101884
vdb-entry
x_refsource_OSVDB
101883
vdb-entry
x_refsource_OSVDB
101885
vdb-entry
x_refsource_OSVDB
101874
vdb-entry
x_refsource_OSVDB
101881
vdb-entry
x_refsource_OSVDB
101878
vdb-entry
x_refsource_OSVDB
101877
vdb-entry
x_refsource_OSVDB
64707
vdb-entry
x_refsource_BID
101880
vdb-entry
x_refsource_OSVDB
101882
vdb-entry
x_refsource_OSVDB
101876
vdb-entry
x_refsource_OSVDB
101875
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now