Hospital Management System(HMS)是一种计算机系统,可以帮助管理与医疗保健相关的信息,并帮助医疗保健提供者有效地完成工作。 Hospital Management System 1.0版本存在SQL注入漏洞,该漏洞源于文件Patientappointment.php存在未知函数,通过参数loginid/password/mobileno/appointmentdate/appointmenttime/patente/dob/doct/city导致 sql 注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Hospital Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3811 | 6.3 MEDIUM | Hospital Management System patientprofile.php sql injection |
| CVE-2023-3809 | 6.3 MEDIUM | Hospital Management System patient.php sql injection |
| CVE-2023-3808 | 6.3 MEDIUM | Hospital Management System patientforgotpassword.php sql injection |
| CVE-2023-3603 | 3.1 LOW | Processing sftp server read may cause null dereference |
| CVE-2023-38632 | async-sockets-cpp 缓冲区错误漏洞 | |
| CVE-2023-38646 | Metabase 安全漏洞 | |
| CVE-2023-37742 | WebBoss.io 跨站脚本漏洞 | |
| CVE-2023-36339 | WebBoss.io 安全漏洞 | |
| CVE-2021-35391 | Deskpro 代码问题漏洞 |
No comments yet