Bus Reservation System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Bus Reservation System version 1.1. The issue resides in the 'pickup_id' parameter, allowing attackers to manipulate database queries. This vulnerability can be exploited using boolean-based, error-based, and time-based blind SQL injection techniques, potentially leading to unauthorized data access from the database.

Impact

Exploitation of this vulnerability allows for SQL injection, where attackers can manipulate database queries to extract, modify, or delete database information.

Reproduction

To reproduce this vulnerability, send a request to the application with a payload in the 'pickup_id' parameter that exploits SQL injection. This can be done using a tool like Burp Suite or manually through a web browser. The application will return a database error message, indicating that the SQL injection was successful.

Added: Dec 15, 2025, 9:22 PM
Updated: Dec 15, 2025, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
9.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.