CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bookingcentre 1Booking System For Hotels Group Apr 23, 2026 Dec 22, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the Not...Show more |
1Bookingcentre 1Booking System For Hotels Group Apr 23, 2026 May 18, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) an...Show more |
1Bookingcentre 1Booking System For Hotels Group Apr 23, 2026 May 18, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter. |
1Bookingcentre 1Booking System For Hotels Group Apr 23, 2026 Feb 20, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter. |
1Bookingcentre 1Booking System For Hotels Group Apr 23, 2026 Feb 20, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter. |