CVE-2023-1058
published 2023-02-27CVE-2023-1058: A vulnerability classified as critical has been found in SourceCodester Doctors Appointment System 1.0. This affects an unknown part of the file…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.76%
51.0th percentile
A vulnerability classified as critical has been found in SourceCodester Doctors Appointment System 1.0. This affects an unknown part of the file create-account.php. The manipulation of the argument newemail leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221823.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| doctors_appointment_system_project | doctors_appointment_system | — | — |
| sourcecodester | doctors_appointment_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
nuclei·CVSS 6.1
CVE-2023-0297 [MEDIUM] PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
Template:
id: CVE-2023-0297
info:
name: PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
author: MrHarshvardhan,DhiyaneshDk
severity: critical
description: |
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
impact: |
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the target system.
remediation: |
Upgrade PyLoad to a version that is not affected by this vulnerability.
reference:
- https://www.exploit-db.com/exploits/51532
- https://huntr.dev/bounties/3fd606f7-83e1-4265-b083-2e1889a05e65/
- https://nvd.nist.gov/vuln/detail/CVE-2022-1058
- http://packetstormsecurity.com/files/171096/pyL
No writeups or analysis indexed.
https://github.com/E1CHO/cve_hub/blob/main/edoc%20doctor%20appointment%20system/edoc%20doctor%20appointment%20system%20vlun2.pdfhttps://vuldb.com/?ctiid.221823https://vuldb.com/?id.221823https://github.com/E1CHO/cve_hub/blob/main/edoc%20doctor%20appointment%20system/edoc%20doctor%20appointment%20system%20vlun2.pdfhttps://vuldb.com/?ctiid.221823https://vuldb.com/?id.221823
2023-02-27
Published