CVE-2020-29287
CRITICALCar Rental Management System <1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-29287. PoCs published by Mehmet Kelepçe.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Car Rental Management System 1.0 via the 'car_id' and 'id' parameters. The PoC includes crafted HTTP requests that extract database information such as version and user credentials.
Description
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Car Rental Management System 1.0 via the 'car_id' and 'id' parameters. The PoC includes crafted HTTP requests that extract database information such as version and user credentials.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H