CVE-2022-29006: SQL Injection
Published May 11, 2022
·Updated
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
Affected Software
1 affected component
Phpgurukul Directory Management System=1.0
Event History
May 11, 2022
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-29006.
2
What is the severity of CVE-2022-29006?
The severity of CVE-2022-29006 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2022-29006?
The Directory Management System v1.0 by Phpgurukul is affected by CVE-2022-29006.
4
How can attackers exploit CVE-2022-29006?
Attackers can exploit CVE-2022-29006 by exploiting SQL injection vulnerabilities that allow them to bypass authentication.
5
Are there any available references for CVE-2022-29006?
Yes, you can find more information about CVE-2022-29006 in the following references: [Link 1](https://github.com/sudoninja-noob/CVE-2022-29006/blob/main/CVE-2022-29006.txt), [Link 2](https://www.exploit-db.com/exploits/50370).