phptpoint records
7 published records for vendor phptpoint.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-18705No exploit | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOphptpoint · hospital management system · CWE-89 | Critical9.8 | — | 2.0% | Oct 29, 2018 |
39Monitor | CVE-2018-18704No exploit | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.phptpoint · pharmacy management system · CWE-89 | Critical9.8 | — | 1.6% | Oct 29, 2018 |
39Monitor | CVE-2022-34951No exploit | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.phptpoint · pharmacy management system · CWE-89 | Critical9.8 | — | 0.9% | Aug 1, 2022 |
39Monitor | CVE-2022-34954No exploit | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.phptpoint · pharmacy management system · CWE-89 | Critical9.8 | — | 0.9% | Aug 1, 2022 |
39Monitor | CVE-2022-34952No exploit | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.phptpoint · pharmacy management system · CWE-89 | Critical9.8 | — | 0.9% | Aug 1, 2022 |
39Monitor | CVE-2022-34953No exploit | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.phptpoint · pharmacy management system · CWE-89 | Critical9.8 | — | 0.9% | Aug 1, 2022 |
31Monitor | CVE-2018-18703No exploit | PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow phptpoint · mailing server using file handling · CWE-22 | High7.5 | — | 4.1% | Oct 29, 2018 |
- CVE-2018-1870540Plan
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LO
CriticalCVSS 9.8No exploitEPSS 2%phptpoint · hospital management systemOct 29, 2018
- CVE-2018-1870439Monitor
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
CriticalCVSS 9.8No exploitEPSS 2%phptpoint · pharmacy management systemOct 29, 2018
- CVE-2022-3495139Monitor
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
CriticalCVSS 9.8No exploitEPSS 1%phptpoint · pharmacy management systemAug 1, 2022
- CVE-2022-3495439Monitor
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.
CriticalCVSS 9.8No exploitEPSS 1%phptpoint · pharmacy management systemAug 1, 2022
- CVE-2022-3495239Monitor
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
CriticalCVSS 9.8No exploitEPSS 1%phptpoint · pharmacy management systemAug 1, 2022
- CVE-2022-3495339Monitor
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
CriticalCVSS 9.8No exploitEPSS 1%phptpoint · pharmacy management systemAug 1, 2022
- CVE-2018-1870331Monitor
PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow
HighCVSS 7.5No exploitEPSS 4%phptpoint · mailing server using file handlingOct 29, 2018