Phpgurukul

Client Management System

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.11.2024 15:15:08
  • Zuletzt bearbeitet 31.03.2025 19:32:18

Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice p...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 22.10.2024 17:15:04
  • Zuletzt bearbeitet 25.10.2024 18:59:22

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 17.04.2024 19:15:07
  • Zuletzt bearbeitet 10.04.2025 13:40:46

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 19:15:07
  • Zuletzt bearbeitet 10.04.2025 13:40:39

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 18:15:16
  • Zuletzt bearbeitet 10.04.2025 13:41:14

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 18:15:16
  • Zuletzt bearbeitet 10.04.2025 13:41:10

Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 18:15:16
  • Zuletzt bearbeitet 10.04.2025 13:41:06

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 18:15:16
  • Zuletzt bearbeitet 10.04.2025 13:41:00

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.