CVE-2022-29006

CRITICAL NUCLEI

Directory Management System v1.0 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

Exploits (2)

exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50370
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29006

Nuclei Templates (1)

Directory Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

Scores

CVSS v3 9.8
EPSS 0.8742
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
phpgurukul/directory_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026