Khurshid Alam

9 exploits Active since Jan 2023
CVE-2023-0455 WRITEUP HIGH WRITEUP
bumsys < 1.0.3-beta - Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
CVSS 8.8
CVE-2023-0995 WRITEUP MEDIUM WRITEUP
business_management_system < 2.0.1 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.
CVSS 5.4
CVE-2023-1361 WRITEUP MEDIUM WRITEUP
bumsys < 2.0.2 - SQL Injection
SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2.
CVSS 6.5
CVE-2023-1362 WRITEUP MEDIUM WRITEUP
unilogies/bumsys <2.0.2 - Info Disclosure
Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.
CVSS 6.1
CVE-2023-2551 WRITEUP HIGH WRITEUP
bumsys < 2.1.1 - Remote File Inclusion
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
CVSS 8.8
CVE-2023-2552 WRITEUP HIGH WRITEUP
bumsys < 2.1.1 - Cross-Site Request Forgery
Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.
CVSS 8.8
CVE-2023-2553 WRITEUP MEDIUM WRITEUP
bumsys < 2.2.0 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.
CVSS 5.4
CVE-2023-2554 WRITEUP HIGH WRITEUP
unilogies/bumsys <2.2.0 - Path Traversal
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
CVSS 7.2
CVE-2023-2832 WRITEUP HIGH WRITEUP
unilogies/bumsys <2.2.0 - SQL Injection
SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.
CVSS 7.2