Sanjay Singh

22 exploits Active since May 2022
CVE-2022-50948 EXPLOITDB MEDIUM text WORKING POC
Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting
Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which execute in the browser when visitors access the accommodations page.
CVSS 6.4
CVE-2024-33288 EXPLOITDB HIGH text WORKING POC
Prison Management System Using PHP 1.0 - SQL Injection
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
CVSS 7.3
CVE-2022-29004 WRITEUP MEDIUM WRITEUP
e-diary_management_system v1.0 - Cross-Site Scripting via Name Parameter in search-result.php
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
CVSS 6.1
CVE-2022-29005 WRITEUP MEDIUM WRITEUP
Online Birth Certificate System v1.2 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
CVSS 6.1
CVE-2022-29006 WRITEUP CRITICAL WRITEUP
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CVSS 9.8
CVE-2022-29007 WRITEUP CRITICAL WRITEUP
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CVSS 9.8
CVE-2022-29008 WRITEUP MEDIUM WRITEUP
Bus Pass Management System v1.0 - Info Disclosure
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
CVSS 6.5
CVE-2022-29009 WRITEUP CRITICAL WRITEUP
Cyber Cafe Management System Project v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
CVSS 9.8
CVE-2022-43369 WRITEUP MEDIUM WRITEUP
AutoTaxi Stand Management System v1.0 - XSS
AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.
CVSS 6.1
CVE-2022-45217 WRITEUP MEDIUM WRITEUP
Book Store Management System 1.0.0 - Stored Cross-Site Scripting via Level Parameter in Add New System User Module
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.
CVSS 5.4
CVE-2022-45728 WRITEUP MEDIUM WRITEUP
Doctor Appointment Management System 1.0.0 - Cross-Site Scripting
Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVSS 6.1
CVE-2022-45729 WRITEUP MEDIUM WRITEUP
Doctor Appointment Management System 1.0.0 - Cross-Site Scripting via Employee ID Parameter
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.
CVSS 6.1
CVE-2022-46622 WRITEUP MEDIUM WRITEUP
Judging Management System v1.0 - XSS
A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.
CVSS 6.1
CVE-2022-46623 WRITEUP HIGH WRITEUP
Judging Management System v1.0.0 - SQL Injection
Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVSS 7.8
CVE-2022-47102 WRITEUP MEDIUM WRITEUP
Student Study Center Management System V 1.0 - XSS
A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVSS 5.4
EIP-2026-120643 EXPLOITDB text WORKING POC
D-Link DIR-650IN - Authenticated Command Injection
CVE-2022-29009 EXPLOITDB CRITICAL text WORKING POC
Cyber Cafe Management System Project v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
CVSS 9.8
CVE-2022-29007 EXPLOITDB CRITICAL text WORKING POC
Dairy Farm Shop Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
CVSS 9.8
CVE-2022-29006 EXPLOITDB CRITICAL text WORKING POC
Directory Management System v1.0 - SQL Injection
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CVSS 9.8
EIP-2026-110057 EXPLOITDB text WORKING POC
Online Appointment System V1.0 - Cross-Site Scripting (XSS)
EIP-2026-109393 EXPLOITDB text WORKING POC
Medicine Tracker System v1.0 - Sql Injection
CVE-2025-45542 EXPLOITDB HIGH text WORKING POC
CloudClassroom-PHP-Project v1.0 - SQL Injection via Registration Form Pass Parameter
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.
CVSS 7.3