Phpgurukul

Bus Pass Management System

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 20.06.2025 00:00:20
  • Zuletzt bearbeitet 26.06.2025 21:19:24

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulati...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 03.04.2025 07:15:41
  • Zuletzt bearbeitet 11.11.2025 19:15:34

A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible ...

Exploit
  • EPSS 4.55%
  • Veröffentlicht 30.09.2022 19:15:15
  • Zuletzt bearbeitet 12.11.2025 15:15:35

Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 30.09.2022 19:15:15
  • Zuletzt bearbeitet 12.11.2025 15:15:35

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.08.2022 01:15:12
  • Zuletzt bearbeitet 21.11.2024 07:12:35

Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 11.05.2022 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:20

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 16.12.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:43

In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 16.12.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:43

In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.