Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Car Rental Script Project

First CVE: Dec 13, 2017Active for: 9 yearsTotal CVEs: 8

The Car Rental Script Project maintains a single, niche web-based rental-management application that attracts focused research interest despite limited deployment breadth. Vulnerabilities affecting this product skew toward serious outcomes, frequently acquire public exploit code, and recur through web-application input-handling weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and path traversal—patterns typical of PHP or similar scripting frameworks that prioritize rapid development over secure input sanitization. Defenders deploying this script should apply input validation and output encoding consistently and restrict deployment to trusted internal networks where feasible; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Car Rental Script Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2017
8 years ago
Most Recent CVE
Mar 21, 2019
2,684 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-17637CRITICAL
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
Dec 13, 20179.841NOYES
CVE-2017-17906CRITICAL
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
Dec 27, 20179.829NONO
CVE-2018-20648HIGH
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
Mar 21, 20198.826NONO
CVE-2017-17905HIGH
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
Dec 27, 20178.826NONO
CVE-2018-20647MEDIUM
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
Mar 21, 20196.522NONO
CVE-2017-17907MEDIUM
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
Dec 27, 20176.121NONO
CVE-2018-15182MEDIUM
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
Aug 9, 20185.420NONO
CVE-2018-6904MEDIUM
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.
Apr 12, 20185.417NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
25%
25%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (37.5%)
Unknown0 (0.0%)
Required5 (62.5%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Car Rental Script Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Car Rental Script Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Car Rental Script Project's Products

View all 1 CNAs →

Top CWEs