Записи PHPGurukul
1 062 опубликованных записей вендора phpgurukul.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 55
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')460
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')252
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')241
- CWE-352 Cross-Site Request Forgery (CSRF)19
- CWE-434 Unrestricted Upload of File with Dangerous Type18
- CWE-639 Authorization Bypass Through User-Controlled Key7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 062 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2023-0562Proof of concept | PHPGurukul Bank Locker Management System Login index.php sql injectionphpgurukul · bank locker management system · CWE-89 | Критическая9,8 | — | 44,3 % | 28 янв. 2023 г. |
46В плане | CVE-2022-29009Proof of concept | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project vphpgurukul · cyber cafe management system · CWE-89 | Критическая9,8 | — | 22,9 % | 11 мая 2022 г. |
45В плане | CVE-2022-29007Proof of concept | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0phpgurukul · dairy farm shop management system · CWE-89 | Критическая9,8 | — | 19,3 % | 11 мая 2022 г. |
45В плане | CVE-2022-29006Proof of concept | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allowphpgurukul · directory management system · CWE-89 | Критическая9,8 | — | 19,3 % | 11 мая 2022 г. |
44В плане | CVE-2020-5307Proof of concept | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, thephpgurukul · dairy farm shop management system · CWE-89 | Критическая9,8 | — | 15,7 % | 7 янв. 2020 г. |
41В плане | CVE-2022-24263Proof of concept | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via tphpgurukul · hospital management system · CWE-89 | Критическая9,8 | — | 8,2 % | 31 янв. 2022 г. |
41В плане | CVE-2020-10224Эксплойта нет | An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0.phpgurukul · online book store · CWE-434 | Критическая9,8 | — | 5,5 % | 8 мар. 2020 г. |
40В плане | CVE-2020-5192Proof of concept | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are notphpgurukul · hospital management system · CWE-89 | Высокая8,8 | — | 16,8 % | 5 янв. 2020 г. |
40В плане | CVE-2021-26822Эксплойта нет | Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php.phpgurukul · teachers record management system · CWE-89 | Критическая9,8 | — | 4,8 % | 15 февр. 2021 г. |
40В плане | CVE-2023-23162Proof of concept | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.phpgurukul · art gallery management system · CWE-89 | Критическая9,8 | — | 4,4 % | 10 февр. 2023 г. |
40В плане | CVE-2023-23163Proof of concept | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.phpgurukul · art gallery management system · CWE-89 | Критическая9,8 | — | 4,4 % | 10 февр. 2023 г. |
40В плане | CVE-2020-10225Эксплойта нет | An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0.phpgurukul · job portal · CWE-434 | Критическая9,8 | — | 4,3 % | 8 мар. 2020 г. |
40В плане | CVE-2020-25952Эксплойта нет | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers phpgurukul · user registration \& login and user management system · CWE-89 | Критическая9,8 | — | 4,1 % | 16 нояб. 2020 г. |
40В плане | CVE-2023-23156Proof of concept | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the singlephpgurukul · art gallery management system · CWE-89 | Критическая9,8 | — | 3,7 % | 27 февр. 2023 г. |
40В плане | CVE-2023-33338Proof of concept | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.phpgurukul · old age home management system · CWE-89 | Критическая9,8 | — | 3,6 % | 23 мая 2023 г. |
40В плане | CVE-2022-27351Эксплойта нет | Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy.phpgurukul · zoo management system · CWE-434 | Критическая9,8 | — | 3,5 % | 8 апр. 2022 г. |
40В плане | CVE-2021-26765Эксплойта нет | SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sidphpgurukul · student record system · CWE-89 | Критическая9,8 | — | 2,9 % | 22 июл. 2021 г. |
40В плане | CVE-2020-35427Эксплойта нет | SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands anphpgurukul · employee record management system · CWE-89 | Критическая9,8 | — | 2,9 % | 20 июл. 2021 г. |
40В плане | CVE-2024-57687Эксплойта нет | An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows rephpgurukul · land record system · CWE-78 | Критическая9,8 | — | 2,6 % | 10 янв. 2025 г. |
40В плане | CVE-2020-12429Эксплойта нет | Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass iphpgurukul · online course registration · CWE-89 | Критическая9,8 | — | 2,5 % | 28 апр. 2020 г. |
40В плане | CVE-2020-36062Эксплойта нет | Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to tphpgurukul · dairy farm shop management system · CWE-798 | Критическая9,8 | — | 2,3 % | 11 февр. 2022 г. |
40В плане | CVE-2021-33470Эксплойта нет | COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.phpgurukul · covid19 testing management system · CWE-89 | Критическая9,8 | — | 2,3 % | 26 мая 2021 г. |
40В плане | CVE-2021-42224Эксплойта нет | SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.phpgurukul · ifsc code finder · CWE-89 | Критическая9,8 | — | 2,3 % | 13 окт. 2021 г. |
40В плане | CVE-2021-43451Эксплойта нет | SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.phpgurukul · employee record management system · CWE-89 | Критическая9,8 | — | 2,2 % | 1 дек. 2021 г. |
40В плане | CVE-2021-26809Эксплойта нет | PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.phpgurukul · car rental portal · CWE-434 | Критическая9,8 | — | 2,1 % | 17 февр. 2021 г. |
- CVE-2023-056252В плане
PHPGurukul Bank Locker Management System Login index.php sql injection
КритическаяCVSS 9,8Proof of conceptEPSS 44 %phpgurukul · bank locker management system28 янв. 2023 г.
- CVE-2022-2900946В плане
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v
КритическаяCVSS 9,8Proof of conceptEPSS 23 %phpgurukul · cyber cafe management system11 мая 2022 г.
- CVE-2022-2900745В плане
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0
КритическаяCVSS 9,8Proof of conceptEPSS 19 %phpgurukul · dairy farm shop management system11 мая 2022 г.
- CVE-2022-2900645В плане
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allow
КритическаяCVSS 9,8Proof of conceptEPSS 19 %phpgurukul · directory management system11 мая 2022 г.
- CVE-2020-530744В плане
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the
КритическаяCVSS 9,8Proof of conceptEPSS 16 %phpgurukul · dairy farm shop management system7 янв. 2020 г.
- CVE-2022-2426341В плане
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via t
КритическаяCVSS 9,8Proof of conceptEPSS 8 %phpgurukul · hospital management system31 янв. 2022 г.
- CVE-2020-1022441В плане
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %phpgurukul · online book store8 мар. 2020 г.
- CVE-2020-519240В плане
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %phpgurukul · hospital management system5 янв. 2020 г.
- CVE-2021-2682240В плане
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %phpgurukul · teachers record management system15 февр. 2021 г.
- CVE-2023-2316240В плане
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %phpgurukul · art gallery management system10 февр. 2023 г.
- CVE-2023-2316340В плане
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %phpgurukul · art gallery management system10 февр. 2023 г.
- CVE-2020-1022540В плане
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %phpgurukul · job portal8 мар. 2020 г.
- CVE-2020-2595240В плане
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %phpgurukul · user registration \& login and user management system16 нояб. 2020 г.
- CVE-2023-2315640В плане
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single
КритическаяCVSS 9,8Proof of conceptEPSS 4 %phpgurukul · art gallery management system27 февр. 2023 г.
- CVE-2023-3333840В плане
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %phpgurukul · old age home management system23 мая 2023 г.
- CVE-2022-2735140В плане
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpgurukul · zoo management system8 апр. 2022 г.
- CVE-2021-2676540В плане
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpgurukul · student record system22 июл. 2021 г.
- CVE-2020-3542740В плане
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands an
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpgurukul · employee record management system20 июл. 2021 г.
- CVE-2024-5768740В плане
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows re
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpgurukul · land record system10 янв. 2025 г.
- CVE-2020-1242940В плане
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass i
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phpgurukul · online course registration28 апр. 2020 г.
- CVE-2020-3606240В плане
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to t
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · dairy farm shop management system11 февр. 2022 г.
- CVE-2021-3347040В плане
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · covid19 testing management system26 мая 2021 г.
- CVE-2021-4222440В плане
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · ifsc code finder13 окт. 2021 г.
- CVE-2021-4345140В плане
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · employee record management system1 дек. 2021 г.
- CVE-2021-2680940В плане
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · car rental portal17 февр. 2021 г.