Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters. | |
| Title | Online-Exam-System 2015 - 'feedback' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-30T22:07:18.289Z
Reserved: 2026-01-28T18:18:30.525Z
Link: CVE-2020-37051
No data.
Status : Received
Published: 2026-01-30T23:16:10.963
Modified: 2026-01-30T23:16:10.963
Link: CVE-2020-37051
No data.
OpenCVE Enrichment
No data.