Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HMS SQL注入漏洞
Vulnerability Description
HMS是孟加拉国Kabir Khyrul个人开发者的一种基于计算机或网络的医院管理系统。有助于管理医院或任何医疗机构的运作。 HMS 1.0 版本存在安全漏洞,该漏洞源于使用 POST 方式请求 appointment.php 时,存在多个参数会导致SQL注入漏洞。攻击者通过该漏洞可以获取数据库信息。
CVSS Information
N/A
Vulnerability Type
N/A