Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2023-48837

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48836

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48835

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Attacker Value
Unknown

CVE-2023-48834

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-40764

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-40754

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
Attacker Value
Unknown

CVE-2023-3757

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown function of the file /EventBookingCalendar/load.php?controller=GzFront/action=checkout/cid=1/layout=calendar/show_header=T/local=3. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-234432. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-3555

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
A vulnerability was found in GZ Scripts PHP Vacation Rental Script 1.8. It has been classified as problematic. This affects an unknown part of the file /preview.php. The manipulation of the argument page/layout/sort_by/property_id leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233349 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2019-7434

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
0
Attacker Value
Unknown

CVE-2019-7433

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
0