CVE-2022-38637 PoC — Hospital Management System SQL注入漏洞
关联漏洞
标题:
Hospital Management System SQL注入漏洞
(CVE-2022-38637)
Description:Hospital Management System(HMS)是一种计算机系统,可以帮助管理与医疗保健相关的信息,并帮助医疗保健提供者有效地完成工作。 Hospital Management System v1.0 版本存在SQL注入漏洞,该漏洞源于登录页面上的Username 和 Password 参数存在安全问题,攻击者利用该漏洞可以可以从数据库中读取敏感数据、修改数据库数据等。
Description
Hospital Management System 1.0 contains a SQL injection vulnerability via the editid parameter in /HMS/user-login.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
文件快照
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →