Record summary

CVE-2020-29227 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALCar Rental Management System 1.0 - Local File InclusionCVSS 9.8

Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, leading to code execution.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Apply the latest patch or update provided by the vendor to fix the LFI vulnerability in the Car Rental Management System 1.0.

Authorsdaffainfo
Template tagscvecve2020lficar_rental_management_system_projectsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"

Source: ProjectDiscovery

References

3