|
210721
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-22167
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210722
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitiv…
|
CWE-89
SQL Injection
|
CVE-2020-22166
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210723
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive inf…
|
CWE-89
SQL Injection
|
CVE-2020-22165
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210724
|
7.5 |
HIGH
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensi…
|
CWE-89
SQL Injection
|
CVE-2020-22164
|
2024-11-21 14:13 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210725
|
8.8 |
HIGH
Network
|
akaunting
|
akaunting
|
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-22390
|
2024-11-21 14:13 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210726
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
|
CWE-89
SQL Injection
|
CVE-2020-22212
|
2024-11-21 14:13 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210727
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
|
CWE-89
SQL Injection
|
CVE-2020-22211
|
2024-11-21 14:13 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210728
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
|
CWE-89
SQL Injection
|
CVE-2020-22210
|
2024-11-21 14:13 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210729
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
|
CWE-89
SQL Injection
|
CVE-2020-22209
|
2024-11-21 14:13 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210730
|
9.8 |
CRITICAL
Network
|
74cms
|
74cms
|
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
|
CWE-89
SQL Injection
|
CVE-2020-22208
|
2024-11-21 14:13 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|