7.5
CVSSv2

CVE-2009-4386

Published: 22/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote malicious users to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

bookingcentre booking system for hotels group -

Exploits

Name B2D Booking Centre Systems Vendor wwwbookingcentreeu Author Salvatore Fresta aka Drosophila Website wwwsalvatorefrestanet Contact salvatorefresta [at] gmail [dot] com Date 2009-12-11 X INDEX I ABOUT THE APPLICATION II DESCRIPTION III ANA ...