Code-Projects Online Car Rental System
cpe:2.3:a:code-projects:online_car_rental_system:*:*:*:*:*:*:*
- 1.0
A remote code execution vulnerability has been identified in Code-Projects Online Car Rental System version 1.0. The issue arises from the file upload feature, which fails to properly validate file extensions or MIME types. This lack of validation allows attackers to upload PHP shells without any restrictions and execute commands on the server.
Exploitation of this vulnerability allows for remote code execution on the server where the application is hosted.
To reproduce this vulnerability, log into the application and navigate to the file upload feature. Upload a PHP file disguised as a different file type, such as an image. Once the file is uploaded, execute it to run arbitrary commands on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.