Record summary

CVE-2020-37051 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2015affected

Proofs of concept

1

Catalogued exploits

ExploitDBOnline-Exam-System 2015 - 'feedback' SQL InjectionExploitDB exploitby Gus RalphNot analyzed1 file
ExploitDB

PoC details

References

4