CVE-2017-20125
MEDIUMOnline Hotel Booking System Pro 1.2 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20125. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This is a writeup describing an SQL injection vulnerability in Online Hotel Booking System Pro v1.2. It provides the vulnerable endpoint and parameter but lacks executable exploit code.
Description
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
This is a writeup describing an SQL injection vulnerability in Online Hotel Booking System Pro v1.2. It provides the vulnerable endpoint and parameter but lacks executable exploit code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L