vendor:
Rail Pass Management System
by:
Alperen Yozgat
6.1
CVSS
HIGH
Time-Based SQL Injection
89
CWE
Product Name: Rail Pass Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:phpgurukul:rail_pass_management_system:1.0
Platforms Tested: Kali Linux, XAMPP
2023
Rail Pass Management System – ‘searchdata’ Time-Based SQL Injection
The Rail Pass Management System's searchdata parameter in the search function is vulnerable to a time-based SQL injection attack. By sending a crafted payload, an attacker can cause the response time to increase significantly, indicating a successful injection.
Mitigation:
To mitigate this vulnerability, input validation and parameterized queries should be implemented to prevent SQL injection attacks.