Filtered by vendor Phpgurukul
Subscriptions
Total
301 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-51978 | 1 Phpgurukul | 1 Art Gallery Management System | 2024-11-21 | 6.5 Medium |
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection. | ||||
CVE-2023-48722 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | 9.8 Critical |
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
CVE-2023-48720 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | 9.8 Critical |
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
CVE-2023-48718 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | 9.8 Critical |
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
CVE-2023-48016 | 1 Phpgurukul | 1 Restaurant Table Booking System | 2024-11-21 | 7.5 High |
Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter. | ||||
CVE-2023-47446 | 1 Phpgurukul | 1 Pre-school Enrollment System | 2024-11-21 | 5.4 Medium |
Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter. | ||||
CVE-2023-47445 | 1 Phpgurukul | 1 Pre-school Enrollment System | 2024-11-21 | 9.8 Critical |
Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. | ||||
CVE-2023-46584 | 1 Phpgurukul | 1 Nipah Virus Testing Management System | 2024-11-21 | 9.8 Critical |
SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint. | ||||
CVE-2023-46583 | 1 Phpgurukul | 1 Nipah Virus Testing Management System | 2024-11-21 | 6.1 Medium |
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows attackers to execute arbitrary code via a crafted payload injected into the State field. | ||||
CVE-2023-46026 | 1 Phpgurukul | 1 Teacher Subject Allocation Management System | 2024-11-21 | 4.8 Medium |
Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary code via the 'adminname' and 'email' parameters. | ||||
CVE-2023-46025 | 1 Phpgurukul | 1 Teacher Subject Allocation Management System | 2024-11-21 | 4.9 Medium |
SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter. | ||||
CVE-2023-46024 | 1 Phpgurukul | 1 Teacher Subject Allocation Management System | 2024-11-21 | 7.5 High |
SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter. | ||||
CVE-2023-41615 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 9.8 Critical |
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields. | ||||
CVE-2023-41614 | 1 Phpgurukul | 1 Zoo Management System | 2024-11-21 | 4.8 Medium |
A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter. | ||||
CVE-2023-41594 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | 7.5 High |
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters. | ||||
CVE-2023-41593 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | 5.4 Medium |
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters. | ||||
CVE-2023-41575 | 1 Phpgurukul | 1 Blood Bank \& Donor Management System | 2024-11-21 | 5.4 Medium |
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters. | ||||
CVE-2023-3605 | 1 Phpgurukul | 1 Online Shopping Portal | 2024-11-21 | 6.5 Medium |
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-233467. | ||||
CVE-2023-3275 | 1 Phpgurukul | 1 Rail Pass Management System | 2024-11-21 | 6.3 Medium |
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability. | ||||
CVE-2023-39551 | 1 Phpgurukul | 1 Online Security Guards Hiring System | 2024-11-21 | 9.8 Critical |
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php. |