Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-24199

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
Attacker Value
Unknown

CVE-2020-15535

Disclosure Date: July 05, 2020 (last updated February 21, 2025)
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
Attacker Value
Unknown

CVE-2020-11545

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.
Attacker Value
Unknown

CVE-2020-11544

Disclosure Date: April 06, 2020 (last updated February 21, 2025)
An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files.
Attacker Value
Unknown

CVE-2020-5509

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.
Attacker Value
Unknown

CVE-2018-20647

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
0
Attacker Value
Unknown

CVE-2018-20648

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
0
Attacker Value
Unknown

CVE-2018-15182

Disclosure Date: August 09, 2018 (last updated November 27, 2024)
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
0
Attacker Value
Unknown

CVE-2018-6904

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.
0
Attacker Value
Unknown

CVE-2017-17907

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
0