CVE-2020-29227
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.
9.8
CVSS
16.8%
EPSS (exploit prob.)
97th
EPSS percentile
2020-12-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| car_rental_management_system_project | car_rental_management_system | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- https://loopspell.medium.com/cve-2020-29227-unauthenticated-local-file-inclusion-7d3bd2c5c6a5
- https://www.sourcecodester.com/php/14544/car-rental-management-system-using-phpmysqli-source-code.html
- https://loopspell.medium.com/cve-2020-29227-unauthenticated-local-file-inclusion-7d3bd2c5c6a5
- https://www.sourcecodester.com/php/14544/car-rental-management-system-using-phpmysqli-source-code.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-29227