Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-25494 | Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecti Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2017-17829 +1 in the same advisory: …17830 | Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter. Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter. NVD description · AI analysis pending | 7.2 group max | 1% | PoC |
| — | |
| CVE-2017-17828 | Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter. Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — |