Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Unknown
CVE-2024-10807
Disclosure Date: November 05, 2024 (last updated November 07, 2024)
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file hms/doctor/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10806
Disclosure Date: November 05, 2024 (last updated November 07, 2024)
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-46237
Disclosure Date: October 09, 2024 (last updated October 17, 2024)
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.
0
Attacker Value
Unknown
CVE-2020-26630
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
0
Attacker Value
Unknown
CVE-2020-26629
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
0
Attacker Value
Unknown
CVE-2020-26628
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.
0
Attacker Value
Unknown
CVE-2020-26627
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
0
Attacker Value
Unknown
CVE-2023-31498
Disclosure Date: May 11, 2023 (last updated November 15, 2023)
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
0
Attacker Value
Unknown
CVE-2021-35387
Disclosure Date: October 28, 2022 (last updated November 15, 2023)
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
0
Attacker Value
Unknown
CVE-2021-35388
Disclosure Date: October 28, 2022 (last updated November 15, 2023)
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
0