CVE-2024-5137
- EPSS 0.05%
- Veröffentlicht 20.05.2024 10:15:14
- Zuletzt bearbeitet 18.02.2025 15:28:59
A vulnerability classified as problematic was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php of the component Searchbar. The manipulation leads to c...
CVE-2024-5136
- EPSS 0.07%
- Veröffentlicht 20.05.2024 09:15:10
- Zuletzt bearbeitet 21.02.2025 20:32:11
A vulnerability classified as problematic has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /admin/search-directory.php.. The manipulation leads to cross site scripting. It is possible to launch...
CVE-2024-5135
- EPSS 0.13%
- Veröffentlicht 20.05.2024 09:15:09
- Zuletzt bearbeitet 21.02.2025 20:44:01
A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The att...
CVE-2022-31384
- EPSS 0.71%
- Veröffentlicht 16.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:25
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
CVE-2022-31383
- EPSS 0.71%
- Veröffentlicht 16.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:25
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
CVE-2022-31382
- EPSS 0.71%
- Veröffentlicht 16.06.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:25
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
CVE-2022-29006
- EPSS 85.95%
- Veröffentlicht 11.05.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.