header-logo
Suggest Exploit
vendor:
Travel Portal Script
by:
Ihsan Sencan
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Travel Portal Script
Affected Version From: v9.33
Affected Version To: v9.33
Patch Exists: NO
Related CWE: N/A
CPE: a:itechscripts:travel_portal_script
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017

Travel Portal Script v9.33 – SQL Injection Web Vulnerability

Travel Portal Script v9.33 is vulnerable to SQL Injection. Attackers can exploit this vulnerability to gain access to sensitive information stored in the database. The vulnerable parameters are 'pages.php?id', 'hotel.php?hid' and 'holiday.php?hid'. Other files may also be vulnerable. Attackers can also use this vulnerability to add, edit or delete data from the database.

Mitigation:

Developers should ensure that all user input is properly sanitized and validated before being used in SQL queries. They should also use parameterized queries to prevent SQL injection attacks.
Source

Exploit-DB raw data:

# # # # # 
# Vulnerability: Travel Portal Script v9.33 - SQL Injection Web Vulnerability
# Google Dork: Travel Portal Script
# Date:11.01.2017
# Vendor Homepage: http://itechscripts.com/travel-portal-script/
# Script Name: Travel Portal Script
# Script Version: v9.33
# Script Buy Now: http://itechscripts.com/travel-portal-script/
# Author: Ihsan Sencan
# Author Web: http://ihsan.net
# Mail : ihsan[beygir]ihsan[nokta]net
# # # # #
# 
# SQL Injection/Exploit :
# http://localhost/[PATH]/pages.php?id=[SQL]
# http://localhost/[PATH]/hotel.php?hid=[SQL]
# http://localhost/[PATH]/holiday.php?hid=[SQL]
# E.t.c.... Other files, too. There are security vulnerabilities.
# Category,User E.t.c.. Add/Edit/Delete There are security vulnerabilities.
# 
# # # # #