CVE-2009-4618
Tourism Script Bus Script - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.
Exploits (1)
Scores
EPSS
0.0023
EPSS Percentile
45.8%
Classification
CWE
CWE-89
Status
draft
Affected Products (1)
tourismscripts/bus_script
Timeline
Published
Jan 18, 2010
Tracked Since
Feb 18, 2026