CVE-2020-35378

CRITICAL

Online Bus Ticket Reservation 1.0 - SQL Injection via Login Username and Password Fields

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-35378. PoCs published by Sakshi Sharma.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the admin login page of Online Bus Ticket Reservation 1.0, allowing authentication bypass using the payload 'or"=' in both username and password fields.

Description

SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.

Exploits (1)

exploitdb WORKING POC
by Sakshi Sharma · textwebappsphp
https://www.exploit-db.com/exploits/49212

This exploit demonstrates an SQL injection vulnerability in the admin login page of Online Bus Ticket Reservation 1.0, allowing authentication bypass using the payload 'or"=' in both username and password fields.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Online Bus Ticket Reservation 1.0
No auth needed
Prerequisites: Access to the admin login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49212

Scores

CVSS v3 9.8
EPSS 0.0203
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
online_bus_ticket_reservation_project/online_bus_ticket_reservation 1.0
Published Dec 14, 2020
Tracked Since Feb 18, 2026