Commodityrentals' vulnerability profile centers on a specialized portfolio of rental-commerce applications—including ebook, DVD, and CD rental systems along with trade-management tools—that handle transactional workflows and customer data. The recurring weakness class is SQL injection, a perennial input-handling flaw in web-facing rental and booking platforms that can expose underlying databases; the vendor's disclosures frequently acquire public exploit code, making timely remediation critical for deployed instances. Current severity, exploitation status, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Commodityrentals over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4770HIGH SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog acti | Mar 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-0762HIGH SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog acti | Mar 2, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-0763HIGH SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a Cal | Mar 2, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-0761HIGH SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gam | Mar 2, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-0693HIGH SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Feb 23, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-0690HIGH SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog actio | Feb 23, 2010 | 7.5 | 28 | NO | YES |
CVE-2005-3917HIGH SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id p | Nov 30, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Commodityrentals.
Media articles that mention a CVE ID that affects a product developed by Commodityrentals — matched by CVE ID, not by vendor name.