CVE-2022-29006
CRITICAL NUCLEIDirectory Management System v1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-29006. PoCs published by Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Directory Management System 1.0 by injecting a tautology ('1'='1') into the username and password fields, allowing unauthorized admin access.
Description
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
Exploits (2)
This exploit demonstrates an SQL injection authentication bypass in Directory Management System 1.0 by injecting a tautology ('1'='1') into the username and password fields, allowing unauthorized admin access.
The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H