Search Results (8 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-45020 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 7.2 High
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter in a POST request.
CVE-2025-45009 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.
CVE-2025-45010 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.
CVE-2025-45011 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.
CVE-2025-45015 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. The vulnerability allows remote attackers to inject arbitrary JavaScript code via the fromdate and todate parameters.
CVE-2025-45017 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.
CVE-2025-45018 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.
CVE-2025-45019 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the cprice POST request parameter.