7.5
CVSSv2

CVE-2010-4737

Published: 16/02/2011 Updated: 22/09/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote malicious users to execute arbitrary SQL commands via the PropResort parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hotwebscripts hotweb rentals

Exploits

# Author: R4dc0re # Exploit Title: HotWebScripts HotWeb Rentals SQL injection Vulnerability # Date: 05-12-2010 # Vendor or Software Link: wwwhotwebscriptscouk/ # Category:WebApp # Price: £150 # Contact: R4dc0re@yahoofr # Website: www1337dbcom # Greetings to: R0073r(1337dbcom), L0rd CrusAd3r,Sid3^effects and to rest of the 1337db me ...