MYREphp Vacation Rental Software Multiple Vulnerabilities
MYREphp Vacation Rental Software is vulnerable to multiple SQL injection vulnerabilities. An attacker can exploit these vulnerabilities to gain access to sensitive information, execute arbitrary code, and perform other malicious activities. The first vulnerability is a SQL injection vulnerability in the /vacation/1_mobile/search.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable file. The second vulnerability is a Cross Site Scripting (XSS) vulnerability in the /vacation/1_mobile/alert_members.php file. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable file. The third vulnerability is a Blind SQL Injection vulnerability in the /vacation/1_mobile/search.php and /vacation/widgate/request_more_information.php files. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable files.