Projectworlds Railway Reservation System是印度Projectworlds公司的一个铁路订票系统。 Projectworlds Railway Reservation System v1.0版本存在SQL注入漏洞,该漏洞源于train.php的“byname”参数不会验证收到的字符,并且会未经过滤地发送到数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Projectworlds Pvt. Limited | Railway Reservation System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-48685 | 9.8 CRITICAL | Railway Reservation System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-48687 | 9.8 CRITICAL | Railway Reservation System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-48716 | 9.8 CRITICAL | Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-48718 | 9.8 CRITICAL | Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-48720 | 9.8 CRITICAL | Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-48722 | 9.8 CRITICAL | Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi) |
| CVE-2023-44481 | 8.8 HIGH | Leave Management System Project v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-44482 | 8.8 HIGH | Leave Management System Project v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45115 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45116 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45117 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45118 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45119 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45120 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
| CVE-2023-45121 | 8.8 HIGH | Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi) |
No comments yet