Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37771 1 Phpgurukul 1 Art Gallery Management System 2023-08-04 N/A 9.8 CRITICAL
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
CVE-2022-29006 1 Phpgurukul 1 Directory Management System 2022-05-23 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
CVE-2020-12429 1 Phpgurukul 1 Online Course Registration 2020-05-05 7.5 HIGH 9.8 CRITICAL
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.
CVE-2020-10106 1 Phpgurukul 1 Daily Expense Tracker System 2020-03-06 7.5 HIGH 9.8 CRITICAL
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database and to bypass the login prompt.