CVE-2020-35378
CRITICALOnline Bus Ticket Reservation 1.0 - SQL Injection via Login Username and Password Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-35378. PoCs published by Sakshi Sharma.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the admin login page of Online Bus Ticket Reservation 1.0, allowing authentication bypass using the payload 'or"=' in both username and password fields.
Description
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the admin login page of Online Bus Ticket Reservation 1.0, allowing authentication bypass using the payload 'or"=' in both username and password fields.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H