CVE-2022-28093
Critical · CVSS 9.8SCBS Online Sports Venue Reservation System — Local File Inclusion (LFI) leading to Remote Code Execution
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- NVD-CWE-Other
Description
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Search profile — drives PoC discovery
Symbols online-sports-complex-booking-systemSCBSfile inclusioncrafted PHP filevenue reservation
Keywords CVE-2022-28093SCBS Online Sports Venue Reservation Systemlocal file inclusionLFIv1.0wkeyi0x1sports venue booking PHPfile inclusion exploitsourcecodester sports complex
Versions: v1.0
References
- https://github.com/wkeyi0x1/vul-report/blob/main/SCBS%20online%20sports%20venue%20reservation%20system/SCBS%20online%20sports%20venue%20reservation%20system%20v1.0%20-%20File%20Inclusion.md
- https://www.sourcecodester.com/php/15236/online-sports-complex-booking-system-phpmysql-free-source-code.html
- http://scbs.com
- https://github.com/wkeyi0x1/vul-report/blob/main/SCBS%20online%20sports%20venue%20reservation%20system/SCBS%20online%20sports%20venue%20reservation%20system%20v1.0%20-%20File%20Inclusion.md
- https://www.sourcecodester.com/php/15236/online-sports-complex-booking-system-phpmysql-free-source-code.html
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z