CVE-2020-29168
CRITICALOnline Doctor Appointment Booking System - SQL Injection via q Parameter in getuser.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-29168. PoCs published by Ramil Mustafayev.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'q' parameter of getuser.php in the Online Doctor Appointment Booking System PHP and MySQL 1.0. The payload extracts database names via a UNION-based SQL injection attack.
Description
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'q' parameter of getuser.php in the Online Doctor Appointment Booking System PHP and MySQL 1.0. The payload extracts database names via a UNION-based SQL injection attack.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H