Fad Solutions operates a narrowly scoped product portfolio centered on the DRZES HMS healthcare management system. The documented vulnerability surface reflects generic categorization typical of limited or early-stage disclosure records; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fad Solutions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4136MEDIUM Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter. | Dec 9, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-4137HIGH SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter. | Dec 9, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-4366MEDIUM Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php | Dec 20, 2005 | 6.4 | 18 | NO | NO |
CVE-2005-4367MEDIUM Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, p | Dec 20, 2005 | 5.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fad Solutions.
Media articles that mention a CVE ID that affects a product developed by Fad Solutions — matched by CVE ID, not by vendor name.