CVE-2022-29007
CRITICAL EXPLOITED NUCLEIDairy Farm Shop Management System v1.0 - SQL Injection
Title source: llmExploitation Summary
CVE-2022-29007 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Dairy Farm Shop Management System 1.0. By manipulating the username parameter in the login request, an attacker can bypass authentication and log in as an admin without valid credentials.
Description
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
Exploits (2)
This exploit demonstrates an SQL injection authentication bypass in Dairy Farm Shop Management System 1.0. By manipulating the username parameter in the login request, an attacker can bypass authentication and log in as an admin without valid credentials.
The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H