← Back

Commodityrentals

commodityrentals

7 CVEs • 7 products

Products (7)

Click to collapse
Toggle

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Commodityrentals
1Dvd Rentals Script
Apr 29, 2026
Mar 23, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
1Commodityrentals
1Vacation Rental Software
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action.
1Commodityrentals
1Cd Rental Software
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
1Commodityrentals
1Books/ebooks Rentals Script
Apr 29, 2026
Mar 2, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.
1Commodityrentals
1Trade Manager Script
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Commodityrentals
1Video Games Rentals
Apr 29, 2026
Feb 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.
1Commodityrentals
1Commodityrentals
Apr 16, 2026
Nov 30, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.