vendor:
PBBooking
by:
Salvatore Fresta aka Drosophila
7,5
CVSS
HIGH
Multiple Blind SQL Injection
89
CWE
Product Name: PBBooking
Affected Version From: 1.0.4_3
Affected Version To: 1.0.4_3
Patch Exists: NO
Related CWE: N/A
CPE: a:pbbooking:pbbooking:1.0.4_3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
PBBooking 1.0.4_3 Joomla Component Multiple Blind SQL Injection
Some parameters passed to controller.php when the task option is set respectively to save and validate, are not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Mitigation:
No fix available.