vendor:
WebStudio eHotel
by:
Hussin X
8.8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: WebStudio eHotel
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
WebStudio eHotel (pageid) Blind SQL Injection Vulnerability
A Blind SQL Injection vulnerability exists in WebStudio eHotel, which allows an attacker to execute arbitrary SQL commands on the underlying database. The vulnerability is due to insufficient input validation of the 'pageid' parameter in the 'index.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious SQL commands. Successful exploitation of this vulnerability can result in unauthorized access to sensitive information, such as user credentials, and other data stored in the database.
Mitigation:
Input validation should be performed to ensure that user-supplied data is properly sanitized before being used in SQL queries.