HIGH · 7.5

CVE-2008-5874

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails...

Vulnerability Description

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
JoomlahbsCom 5Starhotels_nil_
JoomlahbsCom Allhotels_nil_
JoomlahbsHotel Booking Reservation System_nil_
JoomlaJoomlaAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5874?

CVE-2008-5874 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails...

How severe is CVE-2008-5874?

CVE-2008-5874 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5874?

Check the references section above for vendor advisories and patch information. Affected products include: Joomlahbs Com 5Starhotels, Joomlahbs Com Allhotels, Joomlahbs Hotel Booking Reservation System, Joomla Joomla.