CVE-2022-29006

CRITICAL NUCLEI

Directory Management System v1.0 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

Exploits (2)

nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29006
exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50370

Nuclei Templates (1)

Directory Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

Scores

CVSS v3 9.8
EPSS 0.8595
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-89
Status published

Affected Products (1)

phpgurukul/directory_management_system

Timeline

Published May 11, 2022
Tracked Since Feb 18, 2026