
CVE-2023-40764
https://notcve.org/view.php?id=CVE-2023-40764
28 Aug 2023 — User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-40765
https://notcve.org/view.php?id=CVE-2023-40765
28 Aug 2023 — User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-40766
https://notcve.org/view.php?id=CVE-2023-40766
28 Aug 2023 — User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-40767
https://notcve.org/view.php?id=CVE-2023-40767
28 Aug 2023 — User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2023-40748
https://notcve.org/view.php?id=CVE-2023-40748
28 Aug 2023 — PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-40749
https://notcve.org/view.php?id=CVE-2023-40749
28 Aug 2023 — PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. • https://medium.com/%40mfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-36312
https://notcve.org/view.php?id=CVE-2023-36312
10 Aug 2023 — There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0. • https://medium.com/%40milfortutz/multiple-vulnerabilities-in-phpjabbers-part-1-6703becb4cd4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-36314
https://notcve.org/view.php?id=CVE-2023-36314
10 Aug 2023 — There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0. • https://medium.com/%40milfortutz/multiple-vulnerabilities-in-phpjabbers-part-1-6703becb4cd4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-39776
https://notcve.org/view.php?id=CVE-2023-39776
10 Aug 2023 — A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file. Una vulnerabilidad de carga de archivos en PHPJabbers Ticket Support Script v3.2 permite a atacantes ejecutar código arbitrario cargando un archivo manipulado. • https://medium.com/%40milfortutz/multiple-vulnerabilities-in-phpjabbers-part-2-4fa5e2ccfe2e • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2023-38830
https://notcve.org/view.php?id=CVE-2023-38830
10 Aug 2023 — An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module. una filtración de información en PHPJabbers Yacht Listing Script v1.0 permite a los atacantes exportar los números de tarjetas de crédito de los clientes desde el módulo de Reservas. • https://medium.com/%40milfortutz/multiple-vulnerabilities-in-phpjabbers-part-2-4fa5e2ccfe2e • CWE-668: Exposure of Resource to Wrong Sphere •