Record summary

CVE-2020-35378 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Bus Ticket Reservation 1.0 - SQL InjectionExploitDB exploitby Sakshi SharmaNot analyzed1 file
ExploitDB

PoC details

References

2