See how joomlahbs compares to other vendors in security performance
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or comhbssearch) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the adult parameter in a showhoteldetails action to index.php.
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or comhbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) hid, (2) id, and (3) rid parameters to longDesc.php, and the hid parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) comallhotels or (2) com5starhotels module. NOTE: some of these details are obtained from third party information.
SQL injection vulnerability in the comlowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
SQL injection vulnerability in the Top Hotel (comtophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
SQL injection vulnerability in the comhbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the rtype parameter in a showhoteldetails action to index.php.