Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2020-22169

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22167

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.
Attacker Value
Unknown

CVE-2020-22172

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22170

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22171

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22174

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22176

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
Attacker Value
Unknown

CVE-2020-22165

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-22173

Disclosure Date: June 22, 2021 (last updated February 22, 2025)
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Attacker Value
Unknown

CVE-2020-35745

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.