7.5
CVSSv2

CVE-2012-1672

Published: 11/04/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote malicious users to execute arbitrary SQL commands via the country parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

useasdf 4444 hotel booking portal 0.1

Exploits

'Hotel Booking Portal' SQL Injection (CVE-2012-1672) Mark Stanislav - markstanislav@gmailcom I DESCRIPTION --------------------------------------- A vulnerability exists in getcityphp that allows for SQL injection of the 'country' POST parameter II TESTED VERSION --------------------------------------- 01 III PoC EXPLOIT ------------ ...
Hotel Booking Portal version 01 suffers from a remote SQL injection vulnerability ...