CVE-2008-6215

Bookingcentre Booking System For Hotels Group - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by d3b4g · textwebappsphp
https://www.exploit-db.com/exploits/6876

Scores

EPSS 0.0324
EPSS Percentile 87.0%

Classification

CWE
CWE-79
Status published

Affected Products (2)

bookingcentre/booking_system_for_hotels_group
n/a/n/a

Timeline

Published Feb 20, 2009
Tracked Since Feb 18, 2026