CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter. |
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter. |
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter. |
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter. |
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter. |
1Easytest 1Easytest Online Test Platform Jun 17, 2026 Sep 2, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter. |