CVE-2008-6216
Venalsur Booking Centre Booking System for Hotels Group - SQL Injection via OfertaID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6216. PoCs published by d3b4g.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Booking System for Hotels Group by Venalsur Bookingcenter. The SQLi allows retrieval of user credentials via a UNION-based attack, while the XSS is a simple reflected payload.
Description
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Booking System for Hotels Group by Venalsur Bookingcenter. The SQLi allows retrieval of user credentials via a UNION-based attack, while the XSS is a simple reflected payload.