phpgurukul CVE Vulnerabilities & Metrics

Focus on phpgurukul vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About phpgurukul Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with phpgurukul. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total phpgurukul CVEs: 341
Earliest CVE date: 06 Jan 2020, 01:15 UTC
Latest CVE date: 04 Mar 2025, 04:15 UTC

Latest CVE reference: CVE-2025-1902

Rolling Stats

30-day Count (Rolling): 15
365-day Count (Rolling): 117

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 11.43%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 11.43%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical phpgurukul CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.63

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 149
4.0-6.9 133
7.0-8.9 57
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS phpgurukul CVEs

These are the five CVEs with the highest CVSS scores for phpgurukul, sorted by severity first and recency.

All CVEs for phpgurukul

CVE-2025-1902 phpgurukul vulnerability CVSS: 7.5 04 Mar 2025, 04:15 UTC

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1901 phpgurukul vulnerability CVSS: 7.5 04 Mar 2025, 04:15 UTC

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1900 phpgurukul vulnerability CVSS: 7.5 04 Mar 2025, 04:15 UTC

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /add-table.php. The manipulation of the argument tableno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1894 phpgurukul vulnerability CVSS: 7.5 04 Mar 2025, 02:15 UTC

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1588 phpgurukul vulnerability CVSS: 6.4 23 Feb 2025, 16:15 UTC

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

CVE-2025-1581 phpgurukul vulnerability CVSS: 6.5 23 Feb 2025, 11:15 UTC

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /book-nurse.php?bookid=1. The manipulation of the argument contactname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1578 phpgurukul vulnerability CVSS: 6.5 23 Feb 2025, 08:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument product leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-25357 phpgurukul vulnerability CVSS: 0 13 Feb 2025, 16:16 UTC

A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the email POST request parameter.

CVE-2025-25356 phpgurukul vulnerability CVSS: 0 13 Feb 2025, 16:16 UTC

A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the " todate" POST request parameter.

CVE-2025-25355 phpgurukul vulnerability CVSS: 0 13 Feb 2025, 16:16 UTC

A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.

CVE-2025-25354 phpgurukul vulnerability CVSS: 0 13 Feb 2025, 16:16 UTC

A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.

CVE-2025-25352 phpgurukul vulnerability CVSS: 0 13 Feb 2025, 16:16 UTC

A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.

CVE-2025-25351 phpgurukul vulnerability CVSS: 0 12 Feb 2025, 16:15 UTC

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.

CVE-2025-25349 phpgurukul vulnerability CVSS: 0 12 Feb 2025, 16:15 UTC

PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.

CVE-2024-48170 phpgurukul vulnerability CVSS: 0 10 Feb 2025, 18:15 UTC

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.

CVE-2024-13085 phpgurukul vulnerability CVSS: 7.5 31 Dec 2024, 23:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13084 phpgurukul vulnerability CVSS: 6.5 31 Dec 2024, 22:15 UTC

A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-property.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13083 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 22:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument Admin Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13082 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 21:15 UTC

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/search-property.php. The manipulation of the argument Search By leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13081 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 21:15 UTC

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/contactus.php. The manipulation of the argument Page Description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13080 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 20:15 UTC

A vulnerability was found in PHPGurukul Land Record System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/aboutus.php. The manipulation of the argument Page Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13079 phpgurukul vulnerability CVSS: 6.5 31 Dec 2024, 20:15 UTC

A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/property-details.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13078 phpgurukul vulnerability CVSS: 6.5 31 Dec 2024, 19:15 UTC

A vulnerability has been found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13077 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 19:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/add-property.php. The manipulation of the argument Land Subtype leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13076 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 18:15 UTC

A vulnerability, which was classified as problematic, has been found in PHPGurukul Land Record System 1.0. This issue affects some unknown processing of the file /admin/edit-propertytype.php. The manipulation of the argument Property Type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13075 phpgurukul vulnerability CVSS: 4.0 31 Dec 2024, 18:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. This vulnerability affects unknown code of the file /admin/add-propertytype.php. The manipulation of the argument Land Property Type leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13023 phpgurukul vulnerability CVSS: 3.3 29 Dec 2024, 21:15 UTC

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/search-maid.php of the component Search Maid Page. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13018 phpgurukul vulnerability CVSS: 3.3 29 Dec 2024, 18:15 UTC

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely.

CVE-2024-13017 phpgurukul vulnerability CVSS: 3.3 29 Dec 2024, 17:15 UTC

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/aboutus.php of the component About Us Page. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely.

CVE-2024-13016 phpgurukul vulnerability CVSS: 6.5 29 Dec 2024, 16:15 UTC

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13015 phpgurukul vulnerability CVSS: 3.3 29 Dec 2024, 16:15 UTC

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search-booking-request.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely.

CVE-2024-13014 phpgurukul vulnerability CVSS: 6.5 29 Dec 2024, 15:15 UTC

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-maid.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13013 phpgurukul vulnerability CVSS: 3.3 29 Dec 2024, 14:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Maid Hiring Management System 1.0. Affected is an unknown function of the file /admin/contactus.php of the component Contact Us Page. The manipulation of the argument page title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13000 phpgurukul vulnerability CVSS: 6.5 29 Dec 2024, 03:15 UTC

A vulnerability was found in PHPGurukul Small CRM 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/quote-details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12999 phpgurukul vulnerability CVSS: 6.5 29 Dec 2024, 02:15 UTC

A vulnerability has been found in PHPGurukul Small CRM 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-55268 phpgurukul vulnerability CVSS: 0 06 Dec 2024, 17:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute arbitrary code via the regmobilenumber parameter.

CVE-2024-12230 phpgurukul vulnerability CVSS: 7.5 05 Dec 2024, 15:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/subcategory.php. The manipulation of the argument category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12229 phpgurukul vulnerability CVSS: 7.5 05 Dec 2024, 15:15 UTC

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument search leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12228 phpgurukul vulnerability CVSS: 7.5 05 Dec 2024, 14:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11967 phpgurukul vulnerability CVSS: 7.5 28 Nov 2024, 18:15 UTC

A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11966 phpgurukul vulnerability CVSS: 7.5 28 Nov 2024, 18:15 UTC

A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11965 phpgurukul vulnerability CVSS: 7.5 28 Nov 2024, 17:15 UTC

A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11964 phpgurukul vulnerability CVSS: 7.5 28 Nov 2024, 17:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The manipulation of the argument emailid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11818 phpgurukul vulnerability CVSS: 7.5 27 Nov 2024, 00:15 UTC

A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11817 phpgurukul vulnerability CVSS: 7.5 26 Nov 2024, 23:15 UTC

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11675 phpgurukul vulnerability CVSS: 4.0 26 Nov 2024, 01:15 UTC

A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-48284 phpgurukul vulnerability CVSS: 0 14 Nov 2024, 18:15 UTC

A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary scripts via the searchkey parameter in a POST HTTP request.

CVE-2024-10768 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 19:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10757 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 03:15 UTC

A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/js_data.php. The manipulation of the argument scripts leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10756 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 03:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10755 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 03:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10754 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 03:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dymanic_table.php. The manipulation of the argument scripts leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10753 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 02:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10747 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 00:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_th.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10746 phpgurukul vulnerability CVSS: 4.0 04 Nov 2024, 00:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10745 phpgurukul vulnerability CVSS: 4.0 03 Nov 2024, 23:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10744 phpgurukul vulnerability CVSS: 4.0 03 Nov 2024, 23:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/complex_header_2.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10743 phpgurukul vulnerability CVSS: 4.0 03 Nov 2024, 22:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been classified as problematic. Affected is an unknown function of the file /shopping/admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php. The manipulation of the argument value leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10701 phpgurukul vulnerability CVSS: 4.0 02 Nov 2024, 18:15 UTC

A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-51076 phpgurukul vulnerability CVSS: 0 29 Oct 2024, 14:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.

CVE-2024-51075 phpgurukul vulnerability CVSS: 0 29 Oct 2024, 14:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata parameter.

CVE-2024-51181 phpgurukul vulnerability CVSS: 0 29 Oct 2024, 13:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.

CVE-2024-51180 phpgurukul vulnerability CVSS: 0 29 Oct 2024, 13:15 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via the "searchifsccode" parameter.

CVE-2024-10414 phpgurukul vulnerability CVSS: 3.3 27 Oct 2024, 11:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The manipulation of the argument Brand Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions the parameter "phone_number" to be affected. But this might be a mistake because the textbox field label is "Brand Name".

CVE-2024-10331 phpgurukul vulnerability CVSS: 6.5 24 Oct 2024, 11:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue affects some unknown processing of the file /admin/search-vehicle.php. The manipulation of the argument searchinputdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10301 phpgurukul vulnerability CVSS: 5.8 23 Oct 2024, 20:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected is an unknown function of the file /admin/search-medicalcard.php of the component Search. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10300 phpgurukul vulnerability CVSS: 5.8 23 Oct 2024, 20:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/view-enquiry.php of the component View Enquiry Page. The manipulation of the argument viewid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10299 phpgurukul vulnerability CVSS: 5.8 23 Oct 2024, 19:15 UTC

A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/view-card-detail.php of the component Managecard View Detail Page. The manipulation of the argument viewid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10298 phpgurukul vulnerability CVSS: 5.8 23 Oct 2024, 19:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/edit-card-detail.php of the component Managecard Edit Card Detail Page. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-48570 phpgurukul vulnerability CVSS: 0 22 Oct 2024, 17:15 UTC

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

CVE-2024-10192 phpgurukul vulnerability CVSS: 4.0 20 Oct 2024, 07:15 UTC

A vulnerability has been found in PHPGurukul IFSC Code Finder Project 1.0 and classified as problematic. This vulnerability affects unknown code of the file search.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10191 phpgurukul vulnerability CVSS: 4.0 20 Oct 2024, 06:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/book-details.php of the component Booking Details Page. The manipulation of the argument Official Remark leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10162 phpgurukul vulnerability CVSS: 6.5 20 Oct 2024, 01:15 UTC

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php of the component Edit Subdomain Details Page. The manipulation of the argument sadminusername/fullname/emailid/mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "mobilenumber" to be affected. But it must be assumed that other parameters are affected as well.

CVE-2024-10161 phpgurukul vulnerability CVSS: 6.5 20 Oct 2024, 01:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file change-image.php of the component Update Boat Image Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10160 phpgurukul vulnerability CVSS: 6.5 20 Oct 2024, 00:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Boat Booking System 1.0. Affected by this issue is some unknown functionality of the file /admin/bwdates-report-details.php of the component BW Dates Report Page. The manipulation of the argument fdate/tdate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "fdate" to be affected. But it must be assumed "tdate" is affected as well.

CVE-2024-10159 phpgurukul vulnerability CVSS: 7.5 20 Oct 2024, 00:15 UTC

A vulnerability classified as critical was found in PHPGurukul Boat Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/profile.php of the component My Profile Page. The manipulation of the argument sadminusername/fullname/emailid/mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "mobilenumber" to be affected. But it must be assumed that other parameters are affected as well.

CVE-2024-10158 phpgurukul vulnerability CVSS: 5.0 19 Oct 2024, 23:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function session_start. The manipulation leads to session fixiation. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10157 phpgurukul vulnerability CVSS: 7.5 19 Oct 2024, 23:15 UTC

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/password-recovery.php of the component Reset Your Password Page. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10156 phpgurukul vulnerability CVSS: 7.5 19 Oct 2024, 21:15 UTC

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Sign In Page. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10155 phpgurukul vulnerability CVSS: 4.0 19 Oct 2024, 21:15 UTC

A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been classified as problematic. This affects an unknown part of the file book-boat.php?bid=1 of the component Book a Boat Page. The manipulation of the argument phone_number leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10154 phpgurukul vulnerability CVSS: 6.5 19 Oct 2024, 19:15 UTC

A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file status.php of the component Check Booking Status Page. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10153 phpgurukul vulnerability CVSS: 6.5 19 Oct 2024, 18:15 UTC

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file book-boat.php?bid=1 of the component Book a Boat Page. The manipulation of the argument nopeople leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-46237 phpgurukul vulnerability CVSS: 0 09 Oct 2024, 14:15 UTC

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.

CVE-2024-9326 phpgurukul vulnerability CVSS: 7.5 29 Sep 2024, 08:15 UTC

A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-8473 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.

CVE-2024-8472 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.

CVE-2024-8471 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.

CVE-2024-8470 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.

CVE-2024-8469 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.

CVE-2024-8468 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.

CVE-2024-8467 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.

CVE-2024-8466 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.

CVE-2024-8465 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.

CVE-2024-8464 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.

CVE-2024-8463 phpgurukul vulnerability CVSS: 0 05 Sep 2024, 13:15 UTC

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

CVE-2024-40484 phpgurukul vulnerability CVSS: 0 12 Aug 2024, 13:38 UTC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata" parameter.

CVE-2024-40481 phpgurukul vulnerability CVSS: 0 12 Aug 2024, 13:38 UTC

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute arbitrary code via the Contact Us page "message" parameter.

CVE-2024-41333 phpgurukul vulnerability CVSS: 0 06 Aug 2024, 16:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.

CVE-2024-5361 phpgurukul vulnerability CVSS: 6.5 26 May 2024, 11:15 UTC

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/normal-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266273 was assigned to this vulnerability.

CVE-2024-5360 phpgurukul vulnerability CVSS: 6.5 26 May 2024, 11:15 UTC

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/foreigner-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266272.

CVE-2024-5359 phpgurukul vulnerability CVSS: 6.5 26 May 2024, 10:15 UTC

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266271.

CVE-2024-5358 phpgurukul vulnerability CVSS: 6.5 26 May 2024, 09:15 UTC

A vulnerability was found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266270 is the identifier assigned to this vulnerability.

CVE-2024-5357 phpgurukul vulnerability CVSS: 7.5 26 May 2024, 08:15 UTC

A vulnerability has been found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266269 was assigned to this vulnerability.

CVE-2024-5136 phpgurukul vulnerability CVSS: 3.3 20 May 2024, 09:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /admin/search-directory.php.. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265212.

CVE-2024-5135 phpgurukul vulnerability CVSS: 7.5 20 May 2024, 09:15 UTC

A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265211.

CVE-2024-5066 phpgurukul vulnerability CVSS: 6.5 17 May 2024, 20:15 UTC

A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.

CVE-2024-5065 phpgurukul vulnerability CVSS: 7.5 17 May 2024, 20:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.

CVE-2024-5064 phpgurukul vulnerability CVSS: 7.5 17 May 2024, 19:15 UTC

A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.

CVE-2024-3691 phpgurukul vulnerability CVSS: 7.5 12 Apr 2024, 16:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260480.

CVE-2024-3690 phpgurukul vulnerability CVSS: 6.5 12 Apr 2024, 15:15 UTC

A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260479.

CVE-2024-3091 phpgurukul vulnerability CVSS: 3.3 30 Mar 2024, 14:15 UTC

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/search.php of the component Search Request Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258684.

CVE-2024-3090 phpgurukul vulnerability CVSS: 3.3 30 Mar 2024, 13:15 UTC

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/add-ambulance.php of the component Add Ambulance Page. The manipulation of the argument Ambulance Reg No/Driver Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258683.

CVE-2024-3089 phpgurukul vulnerability CVSS: 5.0 30 Mar 2024, 12:15 UTC

A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/manage-ambulance.php of the component Manage Ambulance Page. The manipulation of the argument del leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258682 is the identifier assigned to this vulnerability.

CVE-2024-3087 phpgurukul vulnerability CVSS: 7.5 30 Mar 2024, 11:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258680.

CVE-2024-3086 phpgurukul vulnerability CVSS: 5.0 30 Mar 2024, 09:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument searchdata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258679.

CVE-2024-3085 phpgurukul vulnerability CVSS: 7.5 30 Mar 2024, 09:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258678 is the identifier assigned to this vulnerability.

CVE-2024-3084 phpgurukul vulnerability CVSS: 5.0 30 Mar 2024, 08:15 UTC

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Hire an Ambulance Page. The manipulation of the argument Patient Name/Relative Name/Relative Phone Number/City/State/Message leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258677 was assigned to this vulnerability.

CVE-2024-1822 phpgurukul vulnerability CVSS: 3.3 23 Feb 2024, 16:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unknown function of the file user-bookings.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-254610 is the identifier assigned to this vulnerability.

CVE-2024-0652 phpgurukul vulnerability CVSS: 4.0 18 Jan 2024, 01:15 UTC

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251378 is the identifier assigned to this vulnerability.

CVE-2024-0651 phpgurukul vulnerability CVSS: 6.5 18 Jan 2024, 01:15 UTC

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.

CVE-2024-0476 phpgurukul vulnerability CVSS: 3.3 13 Jan 2024, 06:15 UTC

A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250581 was assigned to this vulnerability.

CVE-2024-0459 phpgurukul vulnerability CVSS: 5.8 12 Jan 2024, 16:15 UTC

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250564.

CVE-2023-51978 phpgurukul vulnerability CVSS: 0 12 Jan 2024, 16:15 UTC

In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.

CVE-2020-26630 phpgurukul vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.

CVE-2020-26629 phpgurukul vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.

CVE-2020-26628 phpgurukul vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.

CVE-2020-26627 phpgurukul vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.

CVE-2024-0364 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 03:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250131.

CVE-2024-0363 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 03:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250130 is the identifier assigned to this vulnerability.

CVE-2024-0362 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 03:15 UTC

A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-250129 was assigned to this vulnerability.

CVE-2024-0361 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 03:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250128.

CVE-2024-0360 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 02:15 UTC

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250127.

CVE-2024-0355 phpgurukul vulnerability CVSS: 5.2 10 Jan 2024, 00:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250122 is the identifier assigned to this vulnerability.

CVE-2024-0286 phpgurukul vulnerability CVSS: 5.0 07 Jan 2024, 18:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249843.

CVE-2023-7173 phpgurukul vulnerability CVSS: 5.0 30 Dec 2023, 12:15 UTC

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249357 was assigned to this vulnerability.

CVE-2023-7172 phpgurukul vulnerability CVSS: 7.5 30 Dec 2023, 09:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Dashboard. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249356.

CVE-2023-7100 phpgurukul vulnerability CVSS: 6.5 25 Dec 2023, 03:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/bwdates-report-details.php. The manipulation of the argument fdate/tdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-7099 phpgurukul vulnerability CVSS: 6.5 25 Dec 2023, 03:15 UTC

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248951.

CVE-2023-7055 phpgurukul vulnerability CVSS: 4.0 22 Dec 2023, 03:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-248742 is the identifier assigned to this vulnerability.

CVE-2023-7054 phpgurukul vulnerability CVSS: 6.5 22 Dec 2023, 02:15 UTC

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248741 was assigned to this vulnerability.

CVE-2023-7053 phpgurukul vulnerability CVSS: 2.6 22 Dec 2023, 02:15 UTC

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248740.

CVE-2023-7052 phpgurukul vulnerability CVSS: 5.0 22 Dec 2023, 01:15 UTC

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248739.

CVE-2023-7051 phpgurukul vulnerability CVSS: 5.0 21 Dec 2023, 22:15 UTC

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248738 is the identifier assigned to this vulnerability.

CVE-2023-7050 phpgurukul vulnerability CVSS: 4.0 21 Dec 2023, 22:15 UTC

A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248737 was assigned to this vulnerability.

CVE-2023-48722 phpgurukul vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48720 phpgurukul vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-48718 phpgurukul vulnerability CVSS: 0 21 Dec 2023, 21:15 UTC

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

CVE-2023-6766 phpgurukul vulnerability CVSS: 5.0 13 Dec 2023, 18:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247896.

CVE-2023-6653 phpgurukul vulnerability CVSS: 5.0 10 Dec 2023, 13:15 UTC

A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.

CVE-2023-6649 phpgurukul vulnerability CVSS: 5.0 10 Dec 2023, 10:15 UTC

A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument searchdata with the input <script>alert(5)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-247342 is the identifier assigned to this vulnerability.

CVE-2023-6648 phpgurukul vulnerability CVSS: 7.5 10 Dec 2023, 09:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-6474 phpgurukul vulnerability CVSS: 5.0 03 Dec 2023, 00:15 UTC

A vulnerability has been found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file manage-phlebotomist.php. The manipulation of the argument pid leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246640.

CVE-2023-6465 phpgurukul vulnerability CVSS: 5.0 02 Dec 2023, 12:15 UTC

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as problematic. This affects an unknown part of the file registered-user-testing.php. The manipulation of the argument regmobilenumber leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246615.

CVE-2023-48016 phpgurukul vulnerability CVSS: 0 01 Dec 2023, 03:15 UTC

Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.

CVE-2023-6442 phpgurukul vulnerability CVSS: 4.0 30 Nov 2023, 21:15 UTC

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246445 was assigned to this vulnerability.

CVE-2023-6402 phpgurukul vulnerability CVSS: 6.5 30 Nov 2023, 15:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file add-phlebotomist.php. The manipulation of the argument empid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246423.

CVE-2023-6297 phpgurukul vulnerability CVSS: 5.0 26 Nov 2023, 23:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file patient-search-report.php of the component Search Report Page. The manipulation of the argument Search By Patient Name with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246123.

CVE-2023-47446 phpgurukul vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.

CVE-2023-47445 phpgurukul vulnerability CVSS: 0 15 Nov 2023, 06:15 UTC

Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

CVE-2023-46026 phpgurukul vulnerability CVSS: 0 14 Nov 2023, 22:15 UTC

Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary code via the 'adminname' and 'email' parameters.

CVE-2023-46025 phpgurukul vulnerability CVSS: 0 14 Nov 2023, 22:15 UTC

SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

CVE-2023-46024 phpgurukul vulnerability CVSS: 0 14 Nov 2023, 22:15 UTC

SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

CVE-2023-6076 phpgurukul vulnerability CVSS: 5.0 10 Nov 2023, 16:15 UTC

A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservation Status Handler. The manipulation of the argument bid leads to information disclosure. The attack can be launched remotely. The identifier VDB-244945 was assigned to this vulnerability.

CVE-2023-6075 phpgurukul vulnerability CVSS: 4.0 10 Nov 2023, 15:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244944.

CVE-2023-6074 phpgurukul vulnerability CVSS: 6.5 10 Nov 2023, 15:15 UTC

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.

CVE-2023-5804 phpgurukul vulnerability CVSS: 7.5 26 Oct 2023, 20:15 UTC

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The identifier VDB-243617 was assigned to this vulnerability.

CVE-2023-5794 phpgurukul vulnerability CVSS: 7.5 26 Oct 2023, 18:15 UTC

A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-243600.

CVE-2023-46584 phpgurukul vulnerability CVSS: 0 25 Oct 2023, 22:15 UTC

SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.

CVE-2023-46583 phpgurukul vulnerability CVSS: 0 25 Oct 2023, 22:15 UTC

Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field.

CVE-2023-5303 phpgurukul vulnerability CVSS: 4.0 30 Sep 2023, 14:15 UTC

A vulnerability, which was classified as problematic, was found in Online Banquet Booking System 1.0. Affected is an unknown function of the file /view-booking-detail.php of the component Account Detail Handler. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. VDB-240942 is the identifier assigned to this vulnerability.

CVE-2023-41614 phpgurukul vulnerability CVSS: 0 21 Sep 2023, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.

CVE-2023-41593 phpgurukul vulnerability CVSS: 0 11 Sep 2023, 18:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

CVE-2023-41575 phpgurukul vulnerability CVSS: 0 08 Sep 2023, 19:15 UTC

Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.

CVE-2023-41615 phpgurukul vulnerability CVSS: 0 08 Sep 2023, 03:15 UTC

Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.

CVE-2023-41594 phpgurukul vulnerability CVSS: 0 08 Sep 2023, 03:15 UTC

Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.

CVE-2023-38890 phpgurukul vulnerability CVSS: 0 18 Aug 2023, 19:15 UTC

Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.

CVE-2023-37690 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVE-2023-37689 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.

CVE-2023-37688 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.

CVE-2023-37687 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.

CVE-2023-37686 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.

CVE-2023-37685 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.

CVE-2023-37684 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.

CVE-2023-37683 phpgurukul vulnerability CVSS: 0 08 Aug 2023, 12:15 UTC

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.

CVE-2023-39551 phpgurukul vulnerability CVSS: 0 04 Aug 2023, 19:15 UTC

PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.

CVE-2023-37772 phpgurukul vulnerability CVSS: 0 01 Aug 2023, 01:15 UTC

Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

CVE-2023-37771 phpgurukul vulnerability CVSS: 0 31 Jul 2023, 16:15 UTC

Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.

CVE-2023-31937 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.

CVE-2023-31936 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.

CVE-2023-31935 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.

CVE-2023-31934 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.

CVE-2023-31933 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.

CVE-2023-31932 phpgurukul vulnerability CVSS: 0 28 Jul 2023, 14:15 UTC

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.

CVE-2023-36942 phpgurukul vulnerability CVSS: 0 27 Jul 2023, 20:15 UTC

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.

CVE-2023-36941 phpgurukul vulnerability CVSS: 0 27 Jul 2023, 18:15 UTC

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.

CVE-2023-37746 phpgurukul vulnerability CVSS: 0 13 Jul 2023, 17:15 UTC

A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.

CVE-2023-37745 phpgurukul vulnerability CVSS: 0 13 Jul 2023, 16:15 UTC

A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.

CVE-2023-37744 phpgurukul vulnerability CVSS: 0 13 Jul 2023, 16:15 UTC

Maid Hiring Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-booking-request.php.

CVE-2023-37743 phpgurukul vulnerability CVSS: 0 13 Jul 2023, 16:15 UTC

A cross-site scripting (XSS) vulnerability in Teacher Subject Allocation System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search text box.

CVE-2023-3605 phpgurukul vulnerability CVSS: 6.4 10 Jul 2023, 20:15 UTC

A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233467.

CVE-2023-36940 phpgurukul vulnerability CVSS: 0 10 Jul 2023, 18:15 UTC

Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.

CVE-2023-36939 phpgurukul vulnerability CVSS: 0 10 Jul 2023, 18:15 UTC

Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.

CVE-2023-36936 phpgurukul vulnerability CVSS: 0 10 Jul 2023, 18:15 UTC

Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.

CVE-2023-36375 phpgurukul vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.

CVE-2023-36376 phpgurukul vulnerability CVSS: 0 10 Jul 2023, 16:15 UTC

Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.

CVE-2023-34647 phpgurukul vulnerability CVSS: 0 28 Jun 2023, 22:15 UTC

PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2023-34652 phpgurukul vulnerability CVSS: 0 28 Jun 2023, 21:15 UTC

PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.

CVE-2023-33580 phpgurukul vulnerability CVSS: 0 26 Jun 2023, 16:15 UTC

Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.

CVE-2023-34666 phpgurukul vulnerability CVSS: 0 15 Jun 2023, 17:15 UTC

Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.

CVE-2023-3275 phpgurukul vulnerability CVSS: 6.5 15 Jun 2023, 13:15 UTC

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.

CVE-2023-33338 phpgurukul vulnerability CVSS: 0 23 May 2023, 13:15 UTC

Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.

CVE-2023-31498 phpgurukul vulnerability CVSS: 0 11 May 2023, 11:15 UTC

A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.

CVE-2023-1964 phpgurukul vulnerability CVSS: 7.5 09 Apr 2023, 09:15 UTC

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225360.

CVE-2023-1963 phpgurukul vulnerability CVSS: 6.5 09 Apr 2023, 08:15 UTC

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225359.

CVE-2023-1950 phpgurukul vulnerability CVSS: 6.5 08 Apr 2023, 08:15 UTC

A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225337 was assigned to this vulnerability.

CVE-2023-1949 phpgurukul vulnerability CVSS: 6.5 08 Apr 2023, 08:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file change-password.php of the component Change Password Handler. The manipulation of the argument password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225336.

CVE-2023-1948 phpgurukul vulnerability CVSS: 4.0 08 Apr 2023, 08:15 UTC

A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file add-family-member.php of the component Add New Family Member Handler. The manipulation of the argument Member Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225335.

CVE-2023-1909 phpgurukul vulnerability CVSS: 5.8 07 Apr 2023, 17:15 UTC

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225318 is the identifier assigned to this vulnerability.

CVE-2023-26959 phpgurukul vulnerability CVSS: 0 27 Mar 2023, 14:15 UTC

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.

CVE-2023-26958 phpgurukul vulnerability CVSS: 0 27 Mar 2023, 14:15 UTC

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.

CVE-2023-24726 phpgurukul vulnerability CVSS: 0 15 Mar 2023, 14:15 UTC

Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.

CVE-2023-27074 phpgurukul vulnerability CVSS: 0 14 Mar 2023, 15:15 UTC

BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.

CVE-2023-23158 phpgurukul vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page.

CVE-2023-23157 phpgurukul vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page.

CVE-2023-23156 phpgurukul vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

CVE-2023-23155 phpgurukul vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.

CVE-2023-23163 phpgurukul vulnerability CVSS: 0 10 Feb 2023, 20:15 UTC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

CVE-2023-23162 phpgurukul vulnerability CVSS: 0 10 Feb 2023, 20:15 UTC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

CVE-2023-23161 phpgurukul vulnerability CVSS: 0 10 Feb 2023, 20:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

CVE-2023-0563 phpgurukul vulnerability CVSS: 4.0 28 Jan 2023, 23:15 UTC

A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.

CVE-2023-0562 phpgurukul vulnerability CVSS: 7.5 28 Jan 2023, 23:15 UTC

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219716.

CVE-2022-46128 phpgurukul vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.

CVE-2022-45730 phpgurukul vulnerability CVSS: 0 26 Jan 2023, 21:17 UTC

A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function.

CVE-2022-47102 phpgurukul vulnerability CVSS: 0 12 Jan 2023, 22:15 UTC

A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2022-45729 phpgurukul vulnerability CVSS: 0 12 Jan 2023, 22:15 UTC

A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.

CVE-2022-45728 phpgurukul vulnerability CVSS: 0 12 Jan 2023, 22:15 UTC

Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2022-43369 phpgurukul vulnerability CVSS: 0 06 Dec 2022, 19:15 UTC

AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

CVE-2022-40470 phpgurukul vulnerability CVSS: 0 21 Nov 2022, 16:15 UTC

Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

CVE-2021-37782 phpgurukul vulnerability CVSS: 0 28 Oct 2022, 15:15 UTC

Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.

CVE-2021-37781 phpgurukul vulnerability CVSS: 0 28 Oct 2022, 15:15 UTC

Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.

CVE-2021-35388 phpgurukul vulnerability CVSS: 0 28 Oct 2022, 15:15 UTC

Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.

CVE-2021-35387 phpgurukul vulnerability CVSS: 0 28 Oct 2022, 15:15 UTC

Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

CVE-2022-42206 phpgurukul vulnerability CVSS: 0 21 Oct 2022, 13:15 UTC

PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.

CVE-2022-42205 phpgurukul vulnerability CVSS: 0 21 Oct 2022, 13:15 UTC

PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.

CVE-2022-40943 phpgurukul vulnerability CVSS: 0 30 Sep 2022, 19:15 UTC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-35156 phpgurukul vulnerability CVSS: 0 30 Sep 2022, 19:15 UTC

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

CVE-2022-35155 phpgurukul vulnerability CVSS: 0 30 Sep 2022, 19:15 UTC

Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

CVE-2022-40944 phpgurukul vulnerability CVSS: 0 30 Sep 2022, 18:15 UTC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

CVE-2022-40925 phpgurukul vulnerability CVSS: 0 26 Sep 2022, 13:15 UTC

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.

CVE-2022-40924 phpgurukul vulnerability CVSS: 0 26 Sep 2022, 13:15 UTC

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.

CVE-2022-40932 phpgurukul vulnerability CVSS: 0 22 Sep 2022, 16:15 UTC

In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.

CVE-2022-36198 phpgurukul vulnerability CVSS: 0 22 Aug 2022, 01:15 UTC

Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php

CVE-2020-23466 phpgurukul vulnerability CVSS: 0 19 Aug 2022, 02:15 UTC

Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.

CVE-2022-2804 phpgurukul vulnerability CVSS: 0 12 Aug 2022, 20:15 UTC

A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.

CVE-2022-2803 phpgurukul vulnerability CVSS: 0 12 Aug 2022, 20:15 UTC

A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206249 was assigned to this vulnerability.

CVE-2022-33075 phpgurukul vulnerability CVSS: 3.5 05 Jul 2022, 18:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

CVE-2022-31897 phpgurukul vulnerability CVSS: 4.3 29 Jun 2022, 01:15 UTC

SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.

CVE-2022-31384 phpgurukul vulnerability CVSS: 7.5 16 Jun 2022, 17:15 UTC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

CVE-2022-31383 phpgurukul vulnerability CVSS: 7.5 16 Jun 2022, 17:15 UTC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

CVE-2022-31382 phpgurukul vulnerability CVSS: 7.5 16 Jun 2022, 17:15 UTC

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

CVE-2022-31914 phpgurukul vulnerability CVSS: 3.5 16 Jun 2022, 16:15 UTC

Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.

CVE-2022-30930 phpgurukul vulnerability CVSS: 4.3 14 Jun 2022, 17:15 UTC

Tourism Management System Version: V 3.2 is affected by: Cross Site Request Forgery (CSRF).

CVE-2021-4232 phpgurukul vulnerability CVSS: 4.3 26 May 2022, 17:15 UTC

A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function of the file admin/manage-ticket.php. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. It is possible to launch the attack remotely.

CVE-2022-29005 phpgurukul vulnerability CVSS: 4.3 23 May 2022, 16:16 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

CVE-2022-29004 phpgurukul vulnerability CVSS: 4.3 23 May 2022, 16:16 UTC

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

CVE-2022-1816 phpgurukul vulnerability CVSS: 3.5 23 May 2022, 12:16 UTC

A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.

CVE-2022-28992 phpgurukul vulnerability CVSS: 6.8 20 May 2022, 13:15 UTC

A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

CVE-2022-29009 phpgurukul vulnerability CVSS: 7.5 11 May 2022, 14:15 UTC

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-29008 phpgurukul vulnerability CVSS: 4.0 11 May 2022, 14:15 UTC

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

CVE-2022-29007 phpgurukul vulnerability CVSS: 7.5 11 May 2022, 14:15 UTC

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

CVE-2022-29006 phpgurukul vulnerability CVSS: 7.5 11 May 2022, 14:15 UTC

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

CVE-2022-27992 phpgurukul vulnerability CVSS: 6.5 08 Apr 2022, 09:15 UTC

Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.

CVE-2022-27351 phpgurukul vulnerability CVSS: 7.5 08 Apr 2022, 09:15 UTC

Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2021-46110 phpgurukul vulnerability CVSS: 7.5 18 Feb 2022, 21:15 UTC

Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.

CVE-2022-24226 phpgurukul vulnerability CVSS: 5.0 15 Feb 2022, 16:15 UTC

Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.

CVE-2020-36062 phpgurukul vulnerability CVSS: 7.5 11 Feb 2022, 16:15 UTC

Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

CVE-2022-24646 phpgurukul vulnerability CVSS: 7.8 10 Feb 2022, 23:15 UTC

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

CVE-2022-24263 phpgurukul vulnerability CVSS: 7.5 31 Jan 2022, 22:15 UTC

Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

CVE-2021-44317 phpgurukul vulnerability CVSS: 3.5 16 Dec 2021, 19:15 UTC

In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.

CVE-2021-44315 phpgurukul vulnerability CVSS: 5.0 16 Dec 2021, 19:15 UTC

In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

CVE-2021-44966 phpgurukul vulnerability CVSS: 10.0 13 Dec 2021, 15:15 UTC

SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

CVE-2021-44965 phpgurukul vulnerability CVSS: 7.8 13 Dec 2021, 15:15 UTC

Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.

CVE-2021-43137 phpgurukul vulnerability CVSS: 6.8 01 Dec 2021, 20:15 UTC

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

CVE-2021-43451 phpgurukul vulnerability CVSS: 7.5 01 Dec 2021, 19:15 UTC

SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.

CVE-2021-39411 phpgurukul vulnerability CVSS: 4.3 05 Nov 2021, 15:15 UTC

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.

CVE-2021-37808 phpgurukul vulnerability CVSS: 4.3 27 Oct 2021, 17:15 UTC

SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

CVE-2021-37807 phpgurukul vulnerability CVSS: 5.0 27 Oct 2021, 17:15 UTC

An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

CVE-2021-37806 phpgurukul vulnerability CVSS: 4.3 27 Oct 2021, 17:15 UTC

An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

CVE-2021-37805 phpgurukul vulnerability CVSS: 3.5 27 Oct 2021, 17:15 UTC

A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.

CVE-2021-42224 phpgurukul vulnerability CVSS: 7.5 13 Oct 2021, 18:15 UTC

SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.

CVE-2021-42223 phpgurukul vulnerability CVSS: 4.3 13 Oct 2021, 18:15 UTC

Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.

CVE-2021-27822 phpgurukul vulnerability CVSS: 3.5 19 Aug 2021, 14:39 UTC

A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.

CVE-2021-26765 phpgurukul vulnerability CVSS: 7.5 22 Jul 2021, 16:15 UTC

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.

CVE-2021-26764 phpgurukul vulnerability CVSS: 6.5 22 Jul 2021, 16:15 UTC

SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.

CVE-2021-26762 phpgurukul vulnerability CVSS: 6.5 22 Jul 2021, 16:15 UTC

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

CVE-2020-35427 phpgurukul vulnerability CVSS: 7.5 20 Jul 2021, 14:15 UTC

SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2021-28424 phpgurukul vulnerability CVSS: 3.5 01 Jul 2021, 15:15 UTC

A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

CVE-2021-28423 phpgurukul vulnerability CVSS: 6.5 01 Jul 2021, 15:15 UTC

Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.

CVE-2020-22176 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.

CVE-2020-22175 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22174 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22173 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22172 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22171 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22170 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22169 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22168 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22167 phpgurukul vulnerability CVSS: 3.5 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.

CVE-2020-22166 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22165 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-22164 phpgurukul vulnerability CVSS: 5.0 22 Jun 2021, 15:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2021-33470 phpgurukul vulnerability CVSS: 7.5 26 May 2021, 17:15 UTC

COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.

CVE-2021-33469 phpgurukul vulnerability CVSS: 3.5 26 May 2021, 17:15 UTC

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVE-2021-27545 phpgurukul vulnerability CVSS: 4.0 15 Apr 2021, 12:15 UTC

SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.

CVE-2021-27544 phpgurukul vulnerability CVSS: 3.5 15 Apr 2021, 12:15 UTC

Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

CVE-2021-26809 phpgurukul vulnerability CVSS: 7.5 17 Feb 2021, 15:15 UTC

PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

CVE-2021-26822 phpgurukul vulnerability CVSS: 7.5 15 Feb 2021, 21:15 UTC

Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.

CVE-2020-26052 phpgurukul vulnerability CVSS: 3.5 08 Feb 2021, 14:15 UTC

Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.

CVE-2021-26304 phpgurukul vulnerability CVSS: 3.5 29 Jan 2021, 02:15 UTC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.

CVE-2021-26303 phpgurukul vulnerability CVSS: 4.3 29 Jan 2021, 02:15 UTC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

CVE-2020-35745 phpgurukul vulnerability CVSS: 6.5 07 Jan 2021, 21:15 UTC

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVE-2020-35151 phpgurukul vulnerability CVSS: 6.5 21 Dec 2020, 21:15 UTC

The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

CVE-2020-24723 phpgurukul vulnerability CVSS: 3.5 18 Nov 2020, 13:15 UTC

Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.

CVE-2020-28136 phpgurukul vulnerability CVSS: 6.5 17 Nov 2020, 20:15 UTC

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

CVE-2020-25952 phpgurukul vulnerability CVSS: 7.5 16 Nov 2020, 16:15 UTC

SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-25271 phpgurukul vulnerability CVSS: 3.5 08 Oct 2020, 13:15 UTC

PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.

CVE-2020-25270 phpgurukul vulnerability CVSS: 3.5 08 Oct 2020, 13:15 UTC

PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.

CVE-2020-25487 phpgurukul vulnerability CVSS: 4.6 22 Sep 2020, 17:15 UTC

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

CVE-2020-23936 phpgurukul vulnerability CVSS: 7.5 20 Aug 2020, 14:15 UTC

PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

CVE-2020-12429 phpgurukul vulnerability CVSS: 7.5 28 Apr 2020, 20:15 UTC

Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.

CVE-2020-10225 phpgurukul vulnerability CVSS: 7.5 08 Mar 2020, 23:15 UTC

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

CVE-2020-10224 phpgurukul vulnerability CVSS: 7.5 08 Mar 2020, 23:15 UTC

An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

CVE-2020-10107 phpgurukul vulnerability CVSS: 3.5 05 Mar 2020, 13:15 UTC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.

CVE-2020-10106 phpgurukul vulnerability CVSS: 7.5 05 Mar 2020, 13:15 UTC

PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database and to bypass the login prompt.

CVE-2020-5509 phpgurukul vulnerability CVSS: 6.5 14 Jan 2020, 19:15 UTC

PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.

CVE-2020-5193 phpgurukul vulnerability CVSS: 4.3 14 Jan 2020, 18:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.

CVE-2020-5308 phpgurukul vulnerability CVSS: 4.3 09 Jan 2020, 13:15 UTC

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.

CVE-2020-5510 phpgurukul vulnerability CVSS: 10.0 08 Jan 2020, 18:15 UTC

PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

CVE-2020-5307 phpgurukul vulnerability CVSS: 7.5 07 Jan 2020, 19:15 UTC

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.

CVE-2020-5192 phpgurukul vulnerability CVSS: 6.5 06 Jan 2020, 01:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

CVE-2020-5191 phpgurukul vulnerability CVSS: 4.3 06 Jan 2020, 01:15 UTC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.