Vulnerabilities > Phpgurukul

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-26762 SQL Injection vulnerability in PHPgurukul Student Record System 4.0
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.
network
low complexity
phpgurukul CWE-89
8.8
2021-07-22 CVE-2021-26764 SQL Injection vulnerability in PHPgurukul Student Record System 4.0
SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.
network
low complexity
phpgurukul CWE-89
8.8
2021-07-22 CVE-2021-26765 SQL Injection vulnerability in PHPgurukul Student Record System 4.0
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
network
low complexity
phpgurukul CWE-89
critical
9.8
2021-07-20 CVE-2020-35427 SQL Injection vulnerability in PHPgurukul Employee Record Management System 1.1
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
network
low complexity
phpgurukul CWE-89
critical
9.8
2021-07-01 CVE-2021-28423 SQL Injection vulnerability in PHPgurukul Teachers Record Management System 1.0
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.
network
low complexity
phpgurukul CWE-89
8.8
2021-07-01 CVE-2021-28424 Cross-site Scripting vulnerability in PHPgurukul Teachers Record Management System 1.0
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.
network
low complexity
phpgurukul CWE-79
5.4
2021-06-22 CVE-2020-22164 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22165 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22166 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php.
network
low complexity
phpgurukul CWE-89
7.5
2021-06-22 CVE-2020-22167 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php.
network
low complexity
phpgurukul CWE-79
5.4