RSS   Vulnerabilities for 'Rental bike script'   RSS

2019-03-21
 
CVE-2019-7434

CWE-22
 

 
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.

 
 
CVE-2019-7433

CWE-352
 

 
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

 
 
CVE-2019-7432

CWE-74
 

 
PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section.

 


Copyright 2024, cxsecurity.com

 

Back to Top