Description
SQL injection vulnerability in ApPHP Hotel Site 3.x.x allows remote editors to execute arbitrary SQL commands via the pid parameter to index.php.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75390
Exploit x_refsource_misc
http://packetstormsecurity.com/files/132369/ApPHP-Hotel-Site-3.x.x-SQL-Injection.html
Scores
EPSS
0.0114
EPSS Percentile
63.2%
Details
CWE
CWE-89
Status
published
Products (10)
apphp/hotel_site
3.0.9
apphp/hotel_site
3.1.3
apphp/hotel_site
3.2.4
apphp/hotel_site
3.3.0
apphp/hotel_site
3.4.4
apphp/hotel_site
3.5.1
apphp/hotel_site
3.6.1
apphp/hotel_site
3.7.5
apphp/hotel_site
3.8.4
apphp/hotel_site
3.9.1
Published
Jun 22, 2015
Tracked Since
Feb 18, 2026