The Car Rental Script Project maintains a single, niche web-based rental-management application that attracts focused research interest despite limited deployment breadth. Vulnerabilities affecting this product skew toward serious outcomes, frequently acquire public exploit code, and recur through web-application input-handling weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and path traversal—patterns typical of PHP or similar scripting frameworks that prioritize rapid development over secure input sanitization. Defenders deploying this script should apply input validation and output encoding consistently and restrict deployment to trusted internal networks where feasible; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Car Rental Script Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17637CRITICAL Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | Dec 13, 2017 | 9.8 | 41 | NO | YES |
CVE-2017-17906CRITICAL PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter. | Dec 27, 2017 | 9.8 | 29 | NO | NO |
CVE-2018-20648HIGH PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php. | Mar 21, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-17905HIGH PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php. | Dec 27, 2017 | 8.8 | 26 | NO | NO |
CVE-2018-20647MEDIUM PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory. | Mar 21, 2019 | 6.5 | 22 | NO | NO |
CVE-2017-17907MEDIUM PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter. | Dec 27, 2017 | 6.1 | 21 | NO | NO |
CVE-2018-15182MEDIUM PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields. | Aug 9, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-6904MEDIUM PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action. | Apr 12, 2018 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Car Rental Script Project.
Media articles that mention a CVE ID that affects a product developed by Car Rental Script Project — matched by CVE ID, not by vendor name.