CVE-2022-29009
CRITICAL NUCLEICyber Cafe Management System Project v1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-29009. PoCs published by Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Cyber Cafe Management System 1.0. By manipulating the username parameter with a SQL payload, an attacker can bypass authentication and log in as admin.
Description
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
Exploits (2)
This exploit demonstrates an SQL injection authentication bypass in Cyber Cafe Management System 1.0. By manipulating the username parameter with a SQL payload, an attacker can bypass authentication and log in as admin.
The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H