Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-0355 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250122 is the identifier assigned to this vulnerability.
CVE-2024-0364 1 Phpgurukul 1 Hospital Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250131.
CVE-2024-0360 1 Phpgurukul 1 Hospital Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250127.
CVE-2024-0361 1 Phpgurukul 1 Hospital Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250128.
CVE-2024-0362 1 Phpgurukul 1 Hospital Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-250129 was assigned to this vulnerability.
CVE-2024-0363 1 Phpgurukul 1 Hospital Management System 2024-01-12 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250130 is the identifier assigned to this vulnerability.
CVE-2023-48722 1 Phpgurukul 1 Student Result Management System 2023-12-29 N/A 9.8 CRITICAL
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-48720 1 Phpgurukul 1 Student Result Management System 2023-12-29 N/A 9.8 CRITICAL
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-48718 1 Phpgurukul 1 Student Result Management System 2023-12-29 N/A 9.8 CRITICAL
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-7099 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-12-29 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248951.
CVE-2023-7100 1 Phpgurukul 1 Restaurant Table Booking System 2023-12-29 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/bwdates-report-details.php. The manipulation of the argument fdate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248952.
CVE-2023-41615 1 Phpgurukul 1 Zoo Management System 2023-12-28 N/A 9.8 CRITICAL
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
CVE-2023-27074 1 Phpgurukul 1 Bp Monitoring Management System 2023-12-28 N/A 9.8 CRITICAL
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
CVE-2023-0562 1 Phpgurukul 1 Bank Locker Management System 2023-12-28 N/A 9.8 CRITICAL
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219716.
CVE-2023-39551 1 Phpgurukul 1 Online Security Guards Hiring System 2023-12-28 N/A 9.8 CRITICAL
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
CVE-2023-3605 1 Phpgurukul 1 Online Shopping Portal 2023-12-22 N/A 9.1 CRITICAL
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233467.
CVE-2023-1950 1 Phpgurukul 1 Bp Monitoring Management System 2023-12-21 N/A 9.8 CRITICAL
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225337 was assigned to this vulnerability.
CVE-2023-1963 1 Phpgurukul 1 Bank Locker Management System 2023-12-21 N/A 9.8 CRITICAL
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225359.
CVE-2023-1949 1 Phpgurukul 1 Bp Monitoring Management System 2023-12-21 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file change-password.php of the component Change Password Handler. The manipulation of the argument password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225336.
CVE-2023-1964 1 Phpgurukul 1 Bank Locker Management System 2023-12-21 N/A 9.1 CRITICAL
A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225360.
CVE-2023-26959 1 Phpgurukul 1 Park Ticketing Management System 2023-12-21 N/A 9.8 CRITICAL
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
CVE-2023-3275 1 Phpgurukul 1 Rail Pass Management System 2023-12-20 N/A 9.8 CRITICAL
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.
CVE-2023-23155 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 9.8 CRITICAL
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
CVE-2023-24726 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 9.8 CRITICAL
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
CVE-2023-23156 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 9.8 CRITICAL
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
CVE-2023-23162 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 9.8 CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
CVE-2023-23163 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 9.8 CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CVE-2023-5794 1 Phpgurukul 1 Online Railway Catering Management System 2023-12-20 N/A 9.8 CRITICAL
A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-243600.
CVE-2023-6648 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-12-13 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file password-recovery.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247341 was assigned to this vulnerability.
CVE-2023-47445 1 Phpgurukul 1 Pre-school Enrollment System 2023-11-20 N/A 9.8 CRITICAL
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
CVE-2023-6074 1 Phpgurukul 1 Restaurant Table Booking System 2023-11-16 N/A 9.8 CRITICAL
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.
CVE-2020-5307 1 Phpgurukul 1 Dairy Farm Shop Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.
CVE-2021-26765 1 Phpgurukul 1 Student Record System 2023-11-14 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
CVE-2021-42224 1 Phpgurukul 1 Ifsc Code Finder 2023-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CVE-2023-33338 1 Phpgurukul 1 Old Age Home Management System 2023-11-14 N/A 9.8 CRITICAL
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
CVE-2021-26822 1 Phpgurukul 1 Teachers Record Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.
CVE-2022-35156 1 Phpgurukul 1 Bus Pass Management System 2023-11-14 N/A 9.8 CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
CVE-2022-36198 1 Phpgurukul 1 Bus Pass Management System 2023-11-14 N/A 9.8 CRITICAL
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
CVE-2022-2804 1 Phpgurukul 1 Zoo Management System 2023-11-14 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.
CVE-2022-27351 1 Phpgurukul 1 Zoo Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-2803 1 Phpgurukul 1 Zoo Management System 2023-11-14 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206249 was assigned to this vulnerability.
CVE-2021-33470 1 Phpgurukul 1 Covid19 Testing Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
CVE-2020-23936 1 Phpgurukul 1 Vehicle Parking Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
CVE-2021-46110 1 Phpgurukul 1 Online Shopping Portal 2023-11-14 7.5 HIGH 9.8 CRITICAL
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
CVE-2020-5510 1 Phpgurukul 1 Hostel Management System 2023-11-14 10.0 HIGH 9.8 CRITICAL
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
CVE-2021-26809 1 Phpgurukul 1 Car Rental Portal 2023-11-14 7.5 HIGH 9.8 CRITICAL
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
CVE-2023-31498 1 Phpgurukul 1 Hospital Management System 2023-11-14 N/A 9.8 CRITICAL
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
CVE-2022-24263 1 Phpgurukul 1 Hospital Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
CVE-2020-10224 1 Phpgurukul 1 Online Book Store 2023-11-13 7.5 HIGH 9.8 CRITICAL
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.
CVE-2020-10225 1 Phpgurukul 1 Job Portal 2023-11-13 7.5 HIGH 9.8 CRITICAL
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.