CVE-2009-3357
com_hbssearch - SQL Injection via h_id, id, or rid Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3357. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Joomla Hotel Booking System. It provides multiple PoC URLs to exploit unsanitized parameters in various PHP scripts, leading to information disclosure or arbitrary script execution.
Description
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Joomla Hotel Booking System. It provides multiple PoC URLs to exploit unsanitized parameters in various PHP scripts, leading to information disclosure or arbitrary script execution.