Show filters
358 Total Results
Displaying 311-320 of 358
Sort by:
Attacker Value
Unknown

CVE-2021-39411

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.
Attacker Value
Unknown

CVE-2021-37807

Disclosure Date: October 27, 2021 (last updated February 23, 2025)
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
Attacker Value
Unknown

CVE-2021-37805

Disclosure Date: October 27, 2021 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.
Attacker Value
Unknown

CVE-2021-42223

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.
Attacker Value
Unknown

CVE-2021-27822

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.
Attacker Value
Unknown

CVE-2021-26762

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.
Attacker Value
Unknown

CVE-2021-26764

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.
Attacker Value
Unknown

CVE-2021-26765

Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
Attacker Value
Unknown

CVE-2020-35427

Disclosure Date: July 20, 2021 (last updated February 23, 2025)
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
Attacker Value
Unknown

CVE-2021-28423

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.