Show filters
56 Total Results
Displaying 41-50 of 56
Sort by:
Attacker Value
Unknown
CVE-2020-21012
Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
0
Attacker Value
Unknown
CVE-2020-29047
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
0
Attacker Value
Unknown
CVE-2020-23984
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
0
Attacker Value
Unknown
CVE-2020-15536
Disclosure Date: July 05, 2020 (last updated February 21, 2025)
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
0
Attacker Value
Unknown
CVE-2018-17842
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
0
Attacker Value
Unknown
CVE-2018-15191
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
0
Attacker Value
Unknown
CVE-2018-15190
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
0
Attacker Value
Unknown
CVE-2015-1000009
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
0
Attacker Value
Unknown
CVE-2014-4035
Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown
CVE-2012-1672
Disclosure Date: April 11, 2012 (last updated October 04, 2023)
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.
0