CVE-2012-4281

Travelon Express 6.2.2 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4281. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Travelon Express CMS v6.2.2, including SQL injection, persistent XSS, and arbitrary file upload. It provides detailed PoC examples for each vulnerability, including specific endpoints and payloads.

Description

Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php, (3) id parameter to pages.php, (4) fid parameter to admin/airline-edit.php, or (5) cid parameter to admin/customer-edit.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/18871

The exploit demonstrates multiple vulnerabilities in Travelon Express CMS v6.2.2, including SQL injection, persistent XSS, and arbitrary file upload. It provides detailed PoC examples for each vulnerability, including specific endpoints and payloads.

Classification
Working Poc 95%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Reliable
Target: Travelon Express CMS v6.2.2
Auth required
Prerequisites: Access to vulnerable endpoints · Privileged user account for some exploits
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53500
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/81886
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49118
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/81884
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75540
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/81885
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/81883
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18871
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/81882

Scores

EPSS 0.0216
EPSS Percentile 79.8%

Details

CWE
CWE-89
Status published
Products (1)
itechscripts/travelon_express 6.2.2
Published Aug 13, 2012
Tracked Since Feb 18, 2026