Show filters
56 Total Results
Displaying 41-50 of 56
Sort by:
Attacker Value
Unknown

CVE-2020-21012

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
Attacker Value
Unknown

CVE-2020-29047

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
Attacker Value
Unknown

CVE-2020-23984

Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
Attacker Value
Unknown

CVE-2020-15536

Disclosure Date: July 05, 2020 (last updated February 21, 2025)
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
Attacker Value
Unknown

CVE-2018-17842

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
Attacker Value
Unknown

CVE-2018-15191

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
0
Attacker Value
Unknown

CVE-2018-15190

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
0
Attacker Value
Unknown

CVE-2015-1000009

Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
0
Attacker Value
Unknown

CVE-2014-4035

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown

CVE-2012-1672

Disclosure Date: April 11, 2012 (last updated October 04, 2023)
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.
0