CVE-2020-28183
CRITICALSourceCodester Water Billing System 1.0 - SQL Injection via Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-28183. PoCs published by Sarang Tumne.
AI-analyzed exploit summary This exploit demonstrates SQL injection in the 'username' and 'password' parameters of Water Billing System 1.0. It bypasses authentication by injecting SQL conditions, allowing unauthorized access to the application.
Description
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
Exploits (1)
exploitdb
WORKING POC
by Sarang Tumne · textwebappsphp
https://www.exploit-db.com/exploits/49032
This exploit demonstrates SQL injection in the 'username' and 'password' parameters of Water Billing System 1.0. It bypasses authentication by injecting SQL conditions, allowing unauthorized access to the application.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
Water Billing System 1.0
No auth needed
Prerequisites:
Access to the login page of the Water Billing System
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://github.com/sartlabs/0days/tree/main/WBS
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49032
Broken Link x_refsource_misc
https://research-labs.net/search/exploits/water-billing-system-10-username-and-password-parameters-sql-injection
Scores
CVSS v3
9.8
EPSS
0.0253
EPSS Percentile
82.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
water_billing_system_project/water_billing_system
1.0
Published
Nov 17, 2020
Tracked Since
Feb 18, 2026