Rahul Patwari

12 exploits Active since Feb 2023
CVE-2023-23161 WRITEUP MEDIUM WRITEUP
Art Gallery Management System Project 1.0 - Reflected Cross-Site Scripting via artname Parameter
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.
CVSS 6.1
CVE-2023-23162 WRITEUP CRITICAL WRITEUP
Art Gallery Management System Project 1.0 - SQL Injection via cid Parameter
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
CVSS 9.8
CVE-2023-23163 WRITEUP CRITICAL WRITEUP
Art Gallery Management System Project 1.0 - SQL Injection via editid Parameter
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CVSS 9.8
CVE-2023-24726 WRITEUP CRITICAL WRITEUP
Art Gallery Management System v1.0 - SQL Injection
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
CVSS 9.8
CVE-2023-24728 WRITEUP HIGH WRITEUP
Simple Customer Relationship Management System 1.0 - SQL Injection via User Profile Update Contact Parameter
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
CVSS 8.8
CVE-2023-24729 WRITEUP HIGH WRITEUP
Simple Customer Relationship Management System 1.0 - SQL Injection via User Profile Address Parameter
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
CVSS 8.8
CVE-2023-24730 WRITEUP HIGH WRITEUP
Simple Customer Relationship Management System 1.0 - SQL Injection via Company Parameter
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
CVSS 8.8
CVE-2023-24731 WRITEUP HIGH WRITEUP
Simple Customer Relationship Management System 1.0 - SQL Injection via User Profile Update Query Parameter
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
CVSS 8.8
CVE-2023-24732 WRITEUP HIGH WRITEUP
Simple Customer Relationship Management System 1.0 - SQL Injection via Gender Parameter
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
CVSS 8.8
CVE-2023-23161 EXPLOITDB MEDIUM text WORKING POC
Art Gallery Management System Project 1.0 - Reflected Cross-Site Scripting via artname Parameter
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.
CVSS 6.1
CVE-2023-23163 EXPLOITDB CRITICAL text WORKING POC
Art Gallery Management System Project 1.0 - SQL Injection via editid Parameter
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CVSS 9.8
CVE-2023-23162 EXPLOITDB CRITICAL text WORKING POC
Art Gallery Management System Project 1.0 - SQL Injection via cid Parameter
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
CVSS 9.8