CVE-2008-5874

Hotel Booking Reservation System - Joomla! SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.

Exploits (3)

exploitdb WORKING POC VERIFIED
by EcHoLL · perlwebappsphp
https://www.exploit-db.com/exploits/7575
exploitdb WRITEUP VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/7568
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/7567

Scores

EPSS 0.0046
EPSS Percentile 64.4%

Details

CWE
CWE-89
Status published
Products (3)
joomlahbs/com_5starhotels _nil_
joomlahbs/com_allhotels _nil_
joomlahbs/hotel_booking_reservation_system _nil_
Published Jan 08, 2009
Tracked Since Feb 18, 2026