Show filters
131 Total Results
Displaying 101-110 of 131
Sort by:
Attacker Value
Unknown

CVE-2022-24646

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
Attacker Value
Unknown

CVE-2022-24263

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Attacker Value
Unknown

CVE-2021-43631

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
Attacker Value
Unknown

CVE-2021-43630

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.
Attacker Value
Unknown

CVE-2021-43629

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
Attacker Value
Unknown

CVE-2021-43628

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
Attacker Value
Unknown

CVE-2021-39411

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.
Attacker Value
Unknown

CVE-2021-38756

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
Attacker Value
Unknown

CVE-2021-38755

Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
Attacker Value
Unknown

CVE-2021-36351

Disclosure Date: August 06, 2021 (last updated February 23, 2025)
SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.