CVE-2008-5874: SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) comallhotels or (2) com5starhotels module. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5874?
CVE-2008-5874 has a medium severity level due to its potential for remote SQL injection attacks.
How do I fix CVE-2008-5874?
To fix CVE-2008-5874, you should update the Hotel Booking Reservation System and its modules to the latest secure versions.
What are the affected versions in CVE-2008-5874?
CVE-2008-5874 affects all versions of the Hotel Booking Reservation System and its modules com_allhotels and com_5starhotels where the version is listed as _nil_.
What is the impact of exploiting CVE-2008-5874?
Exploiting CVE-2008-5874 allows attackers to execute arbitrary SQL commands benefiting from unauthorized database access.
Which Joomla versions are vulnerable to CVE-2008-5874?
CVE-2008-5874 affects the Hotel Booking Reservation System modules on Joomla versions that utilize the vulnerable components.