Product
car rental script project car rental script
14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-48837
CVE-2023-48836
CVE-2023-48835
CVE-2023-48834
CVE-2023-40764
CVE-2023-40754
CVE-2018-20648
CVE-2018-20647
CVE-2018-15182
CVE-2018-6904
CVE-2017-17907
CVE-2017-17906
CVE-2017-17905
CVE-2017-17637
all versions
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
all versions
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_
all versions
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
all versions
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
all versions
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in
all versions
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) all
all versions
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
all versions
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as
all versions
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
all versions
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.
all versions
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename pa
all versions
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
all versions
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
all versions
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.