Lucene search

K

Zoo Security Vulnerabilities

cve
cve

CVE-2024-5360

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/foreigner-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack can be initiated...

6.3CVSS

7.8AI Score

0.0004EPSS

2024-05-26 11:15 AM
23
cve
cve

CVE-2024-5361

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/normal-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated...

6.3CVSS

7.7AI Score

0.0004EPSS

2024-05-26 11:15 AM
25
cve
cve

CVE-2024-5359

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The...

6.3CVSS

7.3AI Score

0.0004EPSS

2024-05-26 10:15 AM
24
cve
cve

CVE-2024-5358

A vulnerability was found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The...

6.3CVSS

7.3AI Score

0.0004EPSS

2024-05-26 09:15 AM
28
cve
cve

CVE-2024-5357

A vulnerability has been found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely......

7.3CVSS

7.7AI Score

0.0004EPSS

2024-05-26 08:15 AM
26
cve
cve

CVE-2023-41614

A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal...

4.8CVSS

4.9AI Score

0.0004EPSS

2023-09-21 11:15 PM
27
cve
cve

CVE-2023-41615

Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password...

9.8CVSS

10AI Score

0.001EPSS

2023-09-08 03:15 AM
23
cve
cve

CVE-2022-40925

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management...

7.2CVSS

7AI Score

0.001EPSS

2022-09-26 01:15 PM
32
cve
cve

CVE-2022-40924

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management...

7.2CVSS

7AI Score

0.001EPSS

2022-09-26 01:15 PM
25
4
cve
cve

CVE-2022-40932

In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management...

7.2CVSS

7AI Score

0.001EPSS

2022-09-22 04:15 PM
20
6
cve
cve

CVE-2022-2804

A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The...

9.8CVSS

9.5AI Score

0.008EPSS

2022-08-12 08:15 PM
21
2
cve
cve

CVE-2022-2803

A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been...

9.8CVSS

9.7AI Score

0.005EPSS

2022-08-12 08:15 PM
32
4
cve
cve

CVE-2022-33075

A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified...

5.4CVSS

5.2AI Score

0.001EPSS

2022-07-05 06:15 PM
38
2
cve
cve

CVE-2022-31897

SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via...

6.1CVSS

5.9AI Score

0.001EPSS

2022-06-29 01:15 AM
37
3
cve
cve

CVE-2022-31914

Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via...

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-16 04:15 PM
36
2
cve
cve

CVE-2021-4232

A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function of the file admin/manage-ticket.php. The manipulation with the input alert(1) leads to cross site scripting. It is possible to launch the attack...

6.1CVSS

6AI Score

0.001EPSS

2022-05-26 05:15 PM
17
cve
cve

CVE-2022-1816

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input alert(1) leads to an authenticated...

5.4CVSS

5.2AI Score

0.001EPSS

2022-05-23 12:16 PM
41
5
cve
cve

CVE-2022-27351

Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP...

9.8CVSS

9.7AI Score

0.071EPSS

2022-04-08 09:15 AM
55
cve
cve

CVE-2022-27992

Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id...

8.8CVSS

8.9AI Score

0.002EPSS

2022-04-08 09:15 AM
53
cve
cve

CVE-2020-25487

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via...

7.8CVSS

8.1AI Score

0.0005EPSS

2020-09-22 05:15 PM
21
cve
cve

CVE-2020-10257

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc...

9.8CVSS

9.4AI Score

0.101EPSS

2020-03-10 12:15 AM
137
cve
cve

CVE-2005-2349

Zoo 2.10 has Directory...

7.5CVSS

7.5AI Score

0.003EPSS

2019-10-28 02:15 PM
25
cve
cve

CVE-2014-7633

The Dino Zoo (aka com.tappocket.dinozoostar) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-10-21 10:55 AM
17
cve
cve

CVE-2014-5628

The Wonder Zoo - Animal rescue ! (aka com.gameloft.android.ANMP.GloftZRHM) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 01:55 AM
18
cve
cve

CVE-2007-1673

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous...

6.5AI Score

0.041EPSS

2007-05-09 01:19 AM
18
cve
cve

CVE-2006-1269

Buffer overflow in the parse function in parse.c in zoo 2.10 might allow local users to execute arbitrary code via long filename command line arguments, which are not properly handled during archive creation. NOTE: since this issue is local and not setuid, the set of attack scenarios is limited,...

7.3AI Score

0.0004EPSS

2006-03-19 02:02 AM
22
cve
cve

CVE-2006-0855

Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda Spam Firewall, allows user-assisted attackers to execute arbitrary code via a crafted ZOO file that causes the combine function to return a longer string than...

7.5AI Score

0.019EPSS

2006-02-23 09:02 PM
24