CVE-2022-35156

B

us Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:bus_pass_management_system:1.0:*:*:*:*:*:*:*

History

12 Nov 2025, 15:15

Type Values Removed Values Added
References
  • () https://www.exploit-db.com/exploits/50543 -

21 Nov 2024, 07:10

Type Values Removed Values Added
References () http://bus.com - Not Applicable () http://bus.com - Not Applicable
References () http://phpgurukul.com - Not Applicable () http://phpgurukul.com - Not Applicable
References () https://packetstormsecurity.com/files/168555/Bus-Pass-Management-System-1.0-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry () https://packetstormsecurity.com/files/168555/Bus-Pass-Management-System-1.0-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2022-09-30 19:15

Updated : 2025-11-12 15:15


NVD link : CVE-2022-35156

Mitre link : CVE-2022-35156

CVE.ORG link : CVE-2022-35156


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')