Online BUS Booking System Project
Online BUS Booking System Project Online BUS Booking System: vulnerabilidades y CVE
Online BUS Booking System Project Online BUS Booking System tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-45019 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent… |
| CVE-2023-45018 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are… |
| CVE-2023-45015 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent… |
| CVE-2023-45012 | Crítica (9.8) | 0.67% | — | 2 nov 2023 | Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent… |
| CVE-2020-25889 | Crítica (9.8) | 2.8% | — | 8 dic 2020 | Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin… |
| CVE-2020-25273 | Crítica (9.8) | 1.8% | — | 8 oct 2020 | In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection. |
| CVE-2020-25272 | Media (6.1) | 0.87% | — | 8 oct 2020 | In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php. |