Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-5585

Disclosure Date: October 15, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-242170 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-44249

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.
Attacker Value
Unknown

CVE-2020-24195

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
Attacker Value
Unknown

CVE-2020-24196

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.