CVE-2008-5874

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
08/01/2009
Last modified:
09/04/2025

Description

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomlahbs:com_5starhotels:_nil_:*:*:*:*:*:*:*
cpe:2.3:a:joomlahbs:com_allhotels:_nil_:*:*:*:*:*:*:*
cpe:2.3:a:joomlahbs:hotel_booking_reservation_system:_nil_:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*