CVE-2008-5875

Joomla! - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

Exploits (3)

exploitdb WORKING POC VERIFIED
by EcHoLL · perlwebappsphp
https://www.exploit-db.com/exploits/7575
exploitdb WRITEUP VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/7567
exploitdb WRITEUP VERIFIED
by Hussin X · textwebappsphp
https://www.exploit-db.com/exploits/7568

Scores

EPSS 0.0046
EPSS Percentile 64.4%

Details

CWE
CWE-89
Status published
Products (2)
joomlahbs/com_lowcosthotels _nil_
joomlahbs/hotel_booking_reservation_system _nil_
Published Jan 08, 2009
Tracked Since Feb 18, 2026