Onlinegrades Online Grades vulnerabilities
5 known vulnerabilities affecting onlinegrades/online_grades.
Total CVEs
5
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2009-0479P3HIGHCVSS 7.5PoCv3.2.42009-02-09
CVE-2009-0479 [HIGH] CWE-89 CVE-2009-0479: Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote
Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2009-0452P3MEDIUMCVSS 6.8PoCv3.2.42009-02-10
CVE-2009-0452 [MEDIUM] CWE-89 CVE-2009-0452: Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quote
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.
nvd
CVE-2009-2598P3MEDIUMCVSS 6.5PoCv3.2.62009-07-27
CVE-2009-2598 [MEDIUM] CWE-89 CVE-2009-2598: Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) rem
Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute arbitrary SQL commands via the ADD parameter in a mailto action to parents/parents.php.
nvd
CVE-2009-2037P4MEDIUMCVSS 6.8PoC≤ 3.2.5≤ 3.2.6+1 more2009-06-12
CVE-2009-2037 [MEDIUM] CWE-22 CVE-2009-2037: Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and po
Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) GLOBALS[SKIN] parameter to index.php and the (2) skin parameter to admin/admin.php.
nvd
CVE-2009-0453P4MEDIUMCVSS 5.0PoCv3.2.42009-02-10
CVE-2009-0453 [MEDIUM] CWE-200 CVE-2009-0453: Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
nvd