Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-44798

Disclosure Date: September 13, 2024 (last updated September 17, 2024)
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
Attacker Value
Unknown

CVE-2022-35156

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
Attacker Value
Unknown

CVE-2022-35155

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
Attacker Value
Unknown

CVE-2022-36198

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
Attacker Value
Unknown

CVE-2022-29008

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
Attacker Value
Unknown

CVE-2021-44317

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2021-44315

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.