📦 Boat Booking System

by Phpgurukul

🔍 What is Boat Booking System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-8431

HIGH CVSS 7.3 Aug 1, 2025

This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'boatname' parameter in the /admin/add-boat.php file. ...

CVE-2024-10159

HIGH CVSS 7.3 Oct 20, 2024

This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows attackers to manipulate database queries through the profile.php page. Remote attackers can potentially access, m...

CVE-2024-10156

HIGH CVSS 7.3 Oct 19, 2024

This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows attackers to execute arbitrary SQL commands via the username parameter on the admin sign-in page. Attackers can p...

CVE-2025-4156

MEDIUM CVSS 6.3 May 1, 2025

This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to manipulate database queries through the /admin/change-image.php endpoint. Attackers can poten...

CVE-2025-2471

MEDIUM CVSS 6.3 Mar 18, 2025

This is a critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'bid' parameter in boat-details.php. Attacke...

CVE-2024-10161

MEDIUM CVSS 6.3 Oct 20, 2024

This critical vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to upload arbitrary files via the change-image.php component, potentially leading to remote code execution. It...

CVE-2024-10158

MEDIUM CVSS 4.3 Oct 19, 2024

This vulnerability allows attackers to perform session fixation attacks on PHPGurukul Boat Booking System 1.0. By manipulating the session_start function, attackers can force users to use predetermine...

CVE-2024-10153

MEDIUM CVSS 6.3 Oct 19, 2024

This vulnerability allows remote attackers to execute SQL injection attacks on PHPGurukul Boat Booking System 1.0 by manipulating bookingdatefrom/nopeople parameters in the book-boat.php file. Success...