Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-28346 — Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter | Kitploit
Tools/GitHubGitHub/shubham03007/cve-2025-28346
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingDatabase Security
GitHubshubham03007/cve-2025-28346

CVE-2025-28346

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

View Repository
181 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

[Vulnerability Type] SQL Injection


Description A Time-Based Blind SQL Injection vulnerability was discovered in Ticket-Booking-App - 1.0 that allows an attacker to execute arbitrary SQL queries on the underlying database. The vulnerable parameter does not properly sanitize user-supplied input, allowing the injection of malicious SQL payloads that rely on time delays to infer the presence of a vulnerability. Unlike classical SQL injection, time-based blind SQL injection does not return data directly. Instead, the attacker determines if the injection was successful based on the time the application takes to respond.

[Vendor of Product] Code-project


[Affected Product Code Base] Ticket-Booking-App - 1.0


[Affected Component] Email Parameter is vulnerable to Time Based SQL Injection


[Attack Type] Remote


[Impact Code execution] true


[Impact Information Disclosure] true


[CVE Impact Other] Time Based SQLI

[Attack Vectors]

  1. Vulnerable Endpoint: Navigate to the following endpoint in the application: Ticket-Booking-App/authenticate.php

  2. Injection Point: In the application's login form or API request, inject the following payload into the email parameter:

%2b(select*from(select(sleep(20)))a)%2b

(This is the URL-encoded form of: +(select * from (select(sleep(20)))a)+)

  1. Verification: Submit the request and observe the server's response time. A delay of approximately 20 seconds confirms that the application is vulnerable to time-based SQL injection.

Impact Successful exploitation of this vulnerability allows a remote unauthenticated attacker to: Confirm the presence of a SQL injection flaw Enumerate the database structure Extract sensitive information from the backend DBMS Perform unauthorized operations depending on the DBMS user privileges This type of vulnerability is particularly dangerous as it can be exploited without any visible output or error messages from the application.

[Reference] https://code-projects.org/ticket-booking-in-php-with-source-code/


[Discoverer] Shubham Ghadge

Use CVE-2025-28346.

Download Tool