CVE-2020-11545: SQL Injection
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (bookcar.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11545?
CVE-2020-11545 is a vulnerability found in Project Worlds Official Car Rental System 1 that allows for multiple SQL injection issues.
What is the severity level of CVE-2020-11545?
The severity level of CVE-2020-11545 is critical with a score of 9.8.
Which software version is affected by CVE-2020-11545?
CVE-2020-11545 affects Project Worlds Official Car Rental System 1 version 1.0.
How can CVE-2020-11545 be exploited?
CVE-2020-11545 can be exploited by an attacker to perform SQL injection attacks through various parameters in the system.
Is there a reference for more information about CVE-2020-11545?
Yes, you can find more information about CVE-2020-11545 at https://frostylabs.net/writeups/cve-2020-11545/.