CVE-2020-22165
- EPSS 36.56%
- Veröffentlicht 22.06.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:13:08
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-22164
- EPSS 2.65%
- Veröffentlicht 22.06.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:07
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-35745
- EPSS 0.38%
- Veröffentlicht 07.01.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:27:59
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
CVE-2020-25271
- EPSS 0.18%
- Veröffentlicht 08.10.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:17:49
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
CVE-2020-5193
- EPSS 0.29%
- Veröffentlicht 14.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:39
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
CVE-2020-5191
- EPSS 3.32%
- Veröffentlicht 06.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:38
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
CVE-2020-5192
- EPSS 41.75%
- Veröffentlicht 06.01.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:39
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.