CVE-2022-29006

CRITICAL NUCLEI

Directory Management System v1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-29006. PoCs published by Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Directory Management System 1.0 by injecting a tautology ('1'='1') into the username and password fields, allowing unauthorized admin access.

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

Exploits (2)

exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50370

This exploit demonstrates an SQL injection authentication bypass in Directory Management System 1.0 by injecting a tautology ('1'='1') into the username and password fields, allowing unauthorized admin access.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Directory Management System v1.0
No auth needed
Prerequisites: Access to the login page · Burp Suite or similar intercepting proxy
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29006

The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Directory Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50370

Scores

CVSS v3 9.8
EPSS 0.1833
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
phpgurukul/directory_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026