CVE-2009-4386
22.12.2009, 23:30
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.
Vendor | Product | Version |
---|---|---|
bookingcentre | booking_system_for_hotels_group | - |
𝑥
= Vulnerable software versions
References