Command School Student Management System
command_school_student_management_system
Vendor: Doug Poulin • 4 CVEs
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Doug Poulin 1Command School Student Management System Apr 29, 2026 Feb 7, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the admini...Show more |
1Doug Poulin 1Command School Student Management System Apr 29, 2026 Feb 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2)...Show more |
1Doug Poulin 1Command School Student Management System Apr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request. |
1Doug Poulin 1Command School Student Management System Apr 29, 2026 Jan 22, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to (1) admin_school_names.php, (2...Show more |