Show filters
3,812 Total Results
Displaying 251-260 of 3,812
Sort by:
Attacker Value
Unknown

CVE-2024-0651

Disclosure Date: January 18, 2024 (last updated February 26, 2025)
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0476

Disclosure Date: January 13, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250581 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0459

Disclosure Date: January 12, 2024 (last updated February 26, 2025)
A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250564.
Attacker Value
Unknown

CVE-2023-51978

Disclosure Date: January 12, 2024 (last updated February 26, 2025)
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2020-26630

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
Attacker Value
Unknown

CVE-2020-26629

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
Attacker Value
Unknown

CVE-2020-26628

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile.
Attacker Value
Unknown

CVE-2020-26627

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
Attacker Value
Unknown

CVE-2024-0364

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250131.
Attacker Value
Unknown

CVE-2024-0363

Disclosure Date: January 10, 2024 (last updated February 25, 2025)
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250130 is the identifier assigned to this vulnerability.