vendor:
Online Doctor Appointment Booking System PHP and Mysql
by:
Ramil Mustafayev
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Doctor Appointment Booking System PHP and Mysql
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:projectworlds:online_doctor_appointment_booking_system_php_and_mysql
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win10 x64, Kali Linux x64
2020
Online Doctor Appointment Booking System PHP and Mysql 1.0 – ‘q’ SQL Injection
An SQL injection vulnerability was discovered in PHP-Doctor-Appointment-System. In getuser.php file, GET parameter 'q' is vulnerable. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.
Mitigation:
Input validation should be used to prevent SQL injection attacks.