Auto Generated CVE annotations [Thu Sep 15 12:24:00 UTC 2022] 🤖

patch-1
GitHub Action 2022-09-15 12:24:00 +00:00
parent c3117b25f2
commit a54f964aca
4 changed files with 17 additions and 5 deletions

View File

@ -11,9 +11,14 @@ info:
- https://github.com/securylight/CVES_write_ups/blob/main/iSpy_connect.pdf
- https://nvd.nist.gov/vuln/detail/CVE-2022-29775
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-29775
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2022-29775
cwe-id: CWE-287
metadata:
verified: true
shodan-query: http.html:"iSpy is running"
verified: "true"
tags: cve,cve2022,ispy,auth-bypass
requests:

View File

@ -3,17 +3,20 @@ id: CVE-2022-32094
info:
name: Hospital Management System v1.0 - SQL Injection
author: arafatansari
severity: high
severity: critical
description: |
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/doctor.php.
reference:
- https://github.com/Danie1233/Hospital-Management-System-v1.0-SQLi-3/
- https://nvd.nist.gov/vuln/detail/CVE-2022-32094
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2022-32094
cwe-id: CWE-89
metadata:
verified: true
shodan-query: http.html:"Hospital Management System"
verified: "true"
tags: cve,cve2022,hms,cms,sqli,auth-bypass
requests:

View File

@ -10,10 +10,13 @@ info:
- https://github.com/Renrao/bug_report/blob/master/blob/main/vendors/itsourcecode.com/hospital-management-system/sql_injection.md
- https://nvd.nist.gov/vuln/detail/CVE-2022-34590
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss-score: 7.2
cve-id: CVE-2022-34590
cwe-id: CWE-89
metadata:
verified: true
shodan-query: http.html:"Hospital Management System"
verified: "true"
tags: cve,cve2022,hms,cms,sqli
requests:

View File

@ -9,11 +9,12 @@ info:
reference:
- https://www.youtube.com/watch?v=m8nW0p69UHU
- https://nvd.nist.gov/vuln/detail/CVE-2022-38637
- https://owasp.org/www-community/attacks/SQL_Injection
classification:
cve-id: CVE-2022-38637
metadata:
verified: true
shodan-query: http.html:"Hospital Management System"
verified: "true"
tags: cve,cve2022,hms,cms,sqli,auth-bypass
requests: