7.5
CVSSv2

CVE-2020-25889

Published: 08/12/2020 Updated: 15/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

online bus booking system project online bus booking system 1.0

Exploits

Online Bus Booking System Project using PHP MySQL version 10 suffers from a remote SQL injection vulnerability that allows for authentication bypass ...

Mailing Lists

Dear Team, Please find attached POC and detailed information for CVE-2020-25889 & CVE-2020-25955 For CVE-2020-25889: # Exploit Title: online bus booking system project using PHP MySQL - SQL Injection # Exploit Author: Krishna Yadav # Vendor Homepage: wwwsourcecodestercom # Software Link: wwwsourcecodestercom/php/14438/onl ...