Description
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-3896 | Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt. |
References
| Link | Providers |
|---|---|
| https://frostylabs.net/writeups/cve-2020-11545/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:35:13.284Z
Reserved: 2020-04-04T00:00:00.000Z
Link: CVE-2020-11545
No data.
Status : Modified
Published: 2020-04-06T16:15:13.503
Modified: 2024-11-21T04:58:07.347
Link: CVE-2020-11545
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD