Vulnerabilities > Phpgurukul

DATE CVE VULNERABILITY TITLE RISK
2020-11-18 CVE-2020-24723 Cross-site Scripting vulnerability in PHPgurukul User Registration & Login and User Management System 2.1
Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.
network
low complexity
phpgurukul CWE-79
4.8
2020-11-17 CVE-2020-28136 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul Tourism Management System 1.0
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
network
low complexity
phpgurukul CWE-434
8.8
2020-11-16 CVE-2020-25952 SQL Injection vulnerability in PHPgurukul User Registration & Login and User Management System 2.1
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
network
low complexity
phpgurukul CWE-89
critical
9.8
2020-10-08 CVE-2020-25271 Cross-site Scripting vulnerability in PHPgurukul Hospital Management System 4.0
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
network
low complexity
phpgurukul CWE-79
5.4
2020-10-08 CVE-2020-25270 Cross-site Scripting vulnerability in PHPgurukul Hostel Management System 2.1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
network
low complexity
phpgurukul CWE-79
5.4
2020-09-22 CVE-2020-25487 SQL Injection vulnerability in PHPgurukul ZOO Management System 1.0
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
local
low complexity
phpgurukul CWE-89
7.8
2020-08-20 CVE-2020-23936 SQL Injection vulnerability in PHPgurukul Vehicle Parking Management System 1.0
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
network
low complexity
phpgurukul CWE-89
critical
9.8
2020-04-28 CVE-2020-12429 SQL Injection vulnerability in PHPgurukul Online Course Registration 2.0
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.
network
low complexity
phpgurukul CWE-89
critical
9.8
2020-03-08 CVE-2020-10225 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul JOB Portal 1.0
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0.
network
low complexity
phpgurukul CWE-434
critical
9.8
2020-03-08 CVE-2020-10224 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul Online Book Store 1.0
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0.
network
low complexity
phpgurukul CWE-434
critical
9.8