CVE-2020-29227

CRITICAL EXPLOITED IN THE WILD NUCLEI

Car Rental Management System 1.0 - Code Injection

Title source: llm

Description

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

Nuclei Templates (1)

Car Rental Management System 1.0 - Local File Inclusion
CRITICALby daffainfo
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"

Scores

CVSS v3 9.8
EPSS 0.9341
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-04-12
InTheWild.io 2021-04-12
Status published
Products (1)
car_rental_management_system_project/car_rental_management_system 1.0
Published Dec 14, 2020
Tracked Since Feb 18, 2026