Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3368. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Joomla Hotel Booking System. It provides multiple PoC URLs to exploit unsanitized parameters in various PHP scripts, leading to information disclosure or arbitrary script execution.
Description
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Joomla Hotel Booking System. It provides multiple PoC URLs to exploit unsanitized parameters in various PHP scripts, leading to information disclosure or arbitrary script execution.