header-logo
Suggest Exploit
vendor:
Easy Travel Portal
by:
L0rd CrusAd3r aka VSN
7,5
CVSS
HIGH
SQLi Vulnerability
89
CWE
Product Name: Easy Travel Portal
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:softwebsnepal:easy_travel_portal
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Easy Travel Portal SQL Vulnerable

This software comes with an admin panel form where you can check the number of listing and do the options like edit/delete. Admin can set email setting form the admin panel. Upload information of your travel country wise. Admin can upload hotel and travel details for each country like hotel photo, rates, hotel location, hotel facilities from admin panel so that visitors to the website can see all these when they log on to website. The vulnerability is a SQLi vulnerability and the demo URL is http://server/traveldemo/tour_packages.asp?country=[sqli], http://server/traveldemo/hoteldetails.asp?id=[sqli], http://server/traveldemo/tourdetails.asp?id=[sqli], http://server/traveldemo/viewnews.asp?id=[sqli].

Mitigation:

Ensure that all user input is properly sanitized and validated before being used in a SQL query.
Source

Exploit-DB raw data: