what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

PHPJabbers Car Park Booking System 3.0 Missing Rate Limiting

PHPJabbers Car Park Booking System 3.0 Missing Rate Limiting
Posted Jan 11, 2024
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Car Park Booking System version 3.0 suffers from multiple missing rate limiting vulnerabilities.

tags | exploit, vulnerability
advisories | CVE-2023-51309, CVE-2023-51310
SHA-256 | f8a75ad9fb77b745bb2d7ce9a94fad0acd8493bb1a0eac630e5bbb0932619c11

PHPJabbers Car Park Booking System 3.0 Missing Rate Limiting

Change Mirror Download
# Exploit Title: PHPJabbers Car Park Booking System v3.0 - Missing Rate Limiting
# Date: 19/12/2023
# Exploit Author: BugsBD Limited
# Discover by: Rahad Chowdhury
# Vendor Homepage: https://www.phpjabbers.com/
# Software Link: https://www.phpjabbers.com/car-park-booking/#sectionDemo
# Version: v3.0
# Tested on: Windows 10, Windows 11, Linux
# CVE-2023-51309

Descriptions:
PHPJabbers Car Park Booking System v3.0 is vulnerable to Rate
limiting. Rate limiting is implemented in web applications and APIs to
prevent abuse, such as brute-force attacks or excessive requests that
could lead to resource exhaustion. When a rate limit is bypassed or
not properly enforced, it opens the door for attackers to carry out
malicious activities more quickly than intended, potentially leading
to unauthorized access, data breaches, or service disruption.

Steps to Reproduce:

1. Login to your dashboard.
2. Goto System Options Menu then open the Email Settings section.
3. Now use any email and name in the Email address and Name field.
4. Check your email.

## Reproduce:
[href](https://github.com/bugsbd/CVE/tree/main/2023/CVE-2023-51309)


# Exploit Title: PHPJabbers Car Park Booking System v3.0 - No Rate Limit on Login Panel
# Date: 19/12/2023
# Exploit Author: BugsBD Limited
# Discover by: Rahad Chowdhury
# Vendor Homepage: https://www.phpjabbers.com/
# Software Link: https://www.phpjabbers.com/car-park-booking/#sectionDemo
# Version: v3.0
# Tested on: Windows 10, Windows 11, Linux
# CVE-2023-51310

A lack of rate limiting in the "Login Section, Forgot Email" feature
of PHPJabbers Car Park Booking System v3.0 allows attackers to send an
excessive amount of reset requests for a legitimate user, leading to a
possible Denial of Service (DoS) via a large amount of generated
e-mail messages.

Steps to Reproduce:
1. Visit this URL
https://demo.phpjabbers.com/1704799030_754/index.php?controller=pjBase&action=pjActionLogin
2. Now use the account mail that is already registered on this website.
3. Capture request data using burp suite and send it to Intruder Tab
4. Configure Intruder and Start Attack
5. Check your email.

## Reproduce:
[href](https://github.com/bugsbd/CVE/tree/main/2023/CVE-2023-51310)
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    0 Files
  • 10
    Jul 10th
    0 Files
  • 11
    Jul 11th
    0 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close