what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

PHPJabbers Bus Reservation System 1.1 Missing Rate Limiting

PHPJabbers Bus Reservation System 1.1 Missing Rate Limiting
Posted Jan 11, 2024
Authored by Rahad Chowdhury, BugsBD Limited

PHPJabbers Bus Reservation System version 1.1 suffers from a missing rate limiting vulnerability.

tags | exploit
advisories | CVE-2023-51316
SHA-256 | db753c223a7023164c3125b719d60e845fdcb8e6cc6a6b7e964b8aa2e5f7582b

PHPJabbers Bus Reservation System 1.1 Missing Rate Limiting

Change Mirror Download
# Exploit Title: PHPJabbers Bus Reservation System v1.1 - No Rate Limit
# Date: 19/12/2023
# Exploit Author: BugsBD Limited
# Discover by: Rahad Chowdhury
# Vendor Homepage: https://www.phpjabbers.com/
# Software Link: https://www.phpjabbers.com/bus-reservation-system/#sectionDemo
# Version: v1.1
# Tested on: Windows 10, Windows 11, Linux
# CVE-2023-51316

Descriptions:
A lack of rate limiting in the "Forgot Email" feature of PHPJabbers
Bus Reservation System v1.1 allows attackers to send an excessive
amount of reset requests for a legitimate user, leading to a possible
Denial of Service (DoS) via a large amount of generated e-mail
messages.

Steps to Reproduce:
1. Visit this URL
https://demo.phpjabbers.com/1704800561_577/index.php?controller=pjAdmin&action=pjActionLogin
2. Now use the account mail that is already registered on this website.
3. Capture request data using burp suite and send it to Intruder Tab
4. Configure Intruder and Start Attack
5. Check your email.

## Reproduce:
[href](https://github.com/bugsbd/CVE/tree/main/2023/CVE-2023-51316)
Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    57 Files
  • 7
    Jun 7th
    6 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    12 Files
  • 11
    Jun 11th
    27 Files
  • 12
    Jun 12th
    38 Files
  • 13
    Jun 13th
    16 Files
  • 14
    Jun 14th
    14 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    16 Files
  • 18
    Jun 18th
    26 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close