Show filters
358 Total Results
Displaying 301-310 of 358
Sort by:
Attacker Value
Unknown

CVE-2022-24226

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
Attacker Value
Unknown

CVE-2020-36062

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
Attacker Value
Unknown

CVE-2022-24646

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
Attacker Value
Unknown

CVE-2022-24263

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
Attacker Value
Unknown

CVE-2021-44317

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2021-44315

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.
Attacker Value
Unknown

CVE-2021-44966

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.
Attacker Value
Unknown

CVE-2021-44965

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.
Attacker Value
Unknown

CVE-2021-43137

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
Attacker Value
Unknown

CVE-2021-43451

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.