Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
Total 903 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37772 1 Phpgurukul 1 Online Shopping Portal 2023-11-14 N/A 8.8 HIGH
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
CVE-2021-46110 1 Phpgurukul 1 Online Shopping Portal 2023-11-14 7.5 HIGH 9.8 CRITICAL
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
CVE-2023-38890 1 Phpgurukul 1 Online Shopping Portal 2023-11-14 N/A 8.8 HIGH
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
CVE-2023-41575 1 Phpgurukul 1 Blood Bank \& Donor Management System 2023-11-14 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
CVE-2020-25270 1 Phpgurukul 1 Hostel Management System 2023-11-14 3.5 LOW 5.4 MEDIUM
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
CVE-2023-34647 1 Phpgurukul 1 Hostel Management System 2023-11-14 N/A 6.1 MEDIUM
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-43137 1 Phpgurukul 1 Hostel Management System 2023-11-14 6.8 MEDIUM 8.8 HIGH
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
CVE-2023-34652 1 Phpgurukul 1 Hostel Management System 2023-11-14 N/A 6.1 MEDIUM
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
CVE-2020-5510 1 Phpgurukul 1 Hostel Management System 2023-11-14 10.0 HIGH 9.8 CRITICAL
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
CVE-2021-26809 1 Phpgurukul 1 Car Rental Portal 2023-11-14 7.5 HIGH 9.8 CRITICAL
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
CVE-2020-28136 1 Phpgurukul 1 Tourism Management System 2023-11-14 6.5 MEDIUM 8.8 HIGH
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
CVE-2022-24263 1 Phpgurukul 1 Hospital Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
CVE-2021-39411 1 Phpgurukul 1 Hospital Management System 2023-11-14 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.
CVE-2022-24226 1 Phpgurukul 1 Hospital Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
CVE-2022-24646 1 Phpgurukul 1 Hospital Management System 2023-11-14 7.8 HIGH 7.5 HIGH
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
CVE-2020-5192 1 Phpgurukul 1 Hospital Management System 2023-11-14 6.5 MEDIUM 8.8 HIGH
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
CVE-2020-22168 1 Phpgurukul 1 Hospital Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22169 1 Phpgurukul 1 Hospital Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22166 1 Phpgurukul 1 Hospital Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22164 1 Phpgurukul 1 Hospital Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.