CVE-2009-4617
Tourismscripts Tourism Script Accomodation Hotel Booking Portal Script - SQL Injection
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4617. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the 'hotel_id' parameter across multiple scripts of the Accommodation Hotel Booking Portal. It uses UNION-based SQLi to extract user credentials (username, password, email) from the 'user' table.
Description
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in the 'hotel_id' parameter across multiple scripts of the Accommodation Hotel Booking Portal. It uses UNION-based SQLi to extract user credentials (username, password, email) from the 'user' table.