g33kyrash Online Banking System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in g33kyrash Online Banking System versions prior to the commit 12dbfa690e5af649fb72d2e5d3674e88d6743455. The issue resides in the file /index.php, where the Username parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, without authentication, allowing attackers to access sensitive database information such as user credentials and financial data.

Impact

Exploitation of this vulnerability allows for unauthorized SQL injection, enabling attackers to extract confidential database information, including user credentials and financial details. This could lead to a complete compromise of the database.

Reproduction

The vulnerability can be reproduced by navigating to the login page and entering a crafted SQL payload in the username field. For example, using an injection that exploits the application's SQL query handling can extract database information, such as the database name, indicating successful exploitation.

Added: Nov 17, 2025, 11:17 AM
Updated: Nov 17, 2025, 11:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.