CVE-2020-37051

Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sunnygkp10:online-exam-system-:2015:*:*:*:*:*:*:*

History

12 Mar 2026, 18:49

Type Values Removed Values Added
References () https://github.com/sunnygkp10/Online-Exam-System-.git - () https://github.com/sunnygkp10/Online-Exam-System-.git - Product
References () https://www.exploit-db.com/exploits/48560 - () https://www.exploit-db.com/exploits/48560 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/online-exam-system-feedback-sql-injection - () https://www.vulncheck.com/advisories/online-exam-system-feedback-sql-injection - Broken Link
First Time Sunnygkp10
Sunnygkp10 online-exam-system-
CPE cpe:2.3:a:sunnygkp10:online-exam-system-:2015:*:*:*:*:*:*:*
Summary
  • (es) Online-Exam-System 2015 contiene una vulnerabilidad de inyección SQL ciega basada en tiempo en el formulario de comentarios que permite a los atacantes extraer hashes de contraseñas de la base de datos. Los atacantes pueden explotar el endpoint 'feed.php' mediante la creación de solicitudes de carga útil maliciosas que utilizan retrasos de tiempo para enumerar sistemáticamente los caracteres de las contraseñas de los usuarios.

30 Jan 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 23:16

Updated : 2026-03-12 18:49


NVD link : CVE-2020-37051

Mitre link : CVE-2020-37051

CVE.ORG link : CVE-2020-37051


JSON object : View

Products Affected

sunnygkp10

  • online-exam-system-
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')