Code-Projects Online Car Rental System File Upload Vulnerability Allowing Remote Code Execution

Vulnerability

A remote code execution vulnerability has been identified in Code-Projects Online Car Rental System version 1.0. The issue arises from the file upload feature, which fails to properly validate file extensions or MIME types. This lack of validation allows attackers to upload PHP shells without any restrictions and execute commands on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where the application is hosted.

Reproduction

To reproduce this vulnerability, log into the application and navigate to the file upload feature. Upload a PHP file disguised as a different file type, such as an image. Once the file is uploaded, execute it to run arbitrary commands on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
5.8
remediation
0.0
relevance
0.0
threat
2.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.