Vendor CVEs
Phpgurukul
All CVEs
1,160 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8466 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8465 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8464 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2024 | SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it. | ||
| CVE-2024-8463 | Cri | 0.64 | 9.9 | 0.01 | Sep 5, 2024 | File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell. | ||
| CVE-2024-40477 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" parameter. | ||
| CVE-2024-30990 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2024 | SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter. | ||
| CVE-2024-30985 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2024 | SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters. | ||
| CVE-2024-30982 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2024 | SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file. | ||
| CVE-2024-30981 | Cri | 0.64 | 9.8 | 0.00 | Apr 17, 2024 | SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL. | ||
| CVE-2024-30980 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2024 | SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page. | ||
| CVE-2024-30998 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2024 | SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component. | ||
| CVE-2024-25350 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2024 | SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters. | ||
| CVE-2020-26629 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server. | ||
| CVE-2023-50035 | Cri | 0.64 | 9.8 | 0.01 | Dec 29, 2023 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed. | ||
| CVE-2023-48722 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2023 | Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-48720 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2023 | Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-48718 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2023 | Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-47445 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2023 | Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. | ||
| CVE-2023-46584 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint. | ||
| CVE-2023-40852 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2023 | SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | ||
| CVE-2023-41615 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields. | ||
| CVE-2023-39551 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php. | ||
| CVE-2023-37771 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. | ||
| CVE-2023-33338 | Cri | 0.64 | 9.8 | 0.04 | May 23, 2023 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | ||
| CVE-2023-31498 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2023 | A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter. | ||
| CVE-2023-26959 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2023 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter. | ||
| CVE-2023-24726 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page. | ||
| CVE-2023-27074 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | ||
| CVE-2023-23155 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login. | ||
| CVE-2021-37782 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. | ||
| CVE-2022-40943 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. | ||
| CVE-2022-35156 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. | ||
| CVE-2022-40944 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. | ||
| CVE-2022-36198 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2022 | Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and… | ||
| CVE-2022-31384 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. | ||
| CVE-2022-31383 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. | ||
| CVE-2022-31382 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. | ||
| CVE-2022-30449 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | ||
| CVE-2022-30448 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | ||
| CVE-2022-27351 | Cri | 0.64 | 9.8 | 0.03 | Apr 8, 2022 | Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2021-46110 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters. | ||
| CVE-2020-36062 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2022 | Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised. | ||
| CVE-2021-44966 | Cri | 0.64 | 9.8 | 0.02 | Dec 13, 2021 | SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system. | ||
| CVE-2021-43451 | Cri | 0.64 | 9.8 | 0.02 | Dec 1, 2021 | SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php. | ||
| CVE-2021-42224 | Cri | 0.64 | 9.8 | 0.02 | Oct 13, 2021 | SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php. | ||
| CVE-2021-38833 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2021 | SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE. | ||
| CVE-2021-26765 | Cri | 0.64 | 9.8 | 0.03 | Jul 22, 2021 | SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php. | ||
| CVE-2020-35427 | Cri | 0.64 | 9.8 | 0.03 | Jul 20, 2021 | SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | ||
| CVE-2021-33470 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2021 | COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel. | ||
| CVE-2021-26809 | Cri | 0.64 | 9.8 | 0.02 | Feb 17, 2021 | PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php. |
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.
- risk 0.64cvss 9.9epss 0.01
File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" parameter.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.
- risk 0.64cvss 9.8epss 0.00
SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
- risk 0.64cvss 9.8epss 0.01
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
- risk 0.64cvss 9.8epss 0.01
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
- risk 0.64cvss 9.8epss 0.01
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.
- risk 0.64cvss 9.8epss 0.01
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
- risk 0.64cvss 9.8epss 0.01
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
- risk 0.64cvss 9.8epss 0.04
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
- risk 0.64cvss 9.8epss 0.02
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
- risk 0.64cvss 9.8epss 0.01
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
- risk 0.64cvss 9.8epss 0.01
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
- risk 0.64cvss 9.8epss 0.01
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
- risk 0.64cvss 9.8epss 0.01
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
- risk 0.64cvss 9.8epss 0.01
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
- risk 0.64cvss 9.8epss 0.01
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and…
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
- risk 0.64cvss 9.8epss 0.03
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
- risk 0.64cvss 9.8epss 0.02
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
- risk 0.64cvss 9.8epss 0.02
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
- risk 0.64cvss 9.8epss 0.02
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
- risk 0.64cvss 9.8epss 0.02
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
Page 2 of 24