CVE-2009-3503 Information

Description

Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.

Reference

http://packetstormsecurity.org/0909-exploits/bpholidaylettings-sql.txt http://secunia.com/advisories/36833 http://www.vupen.com/english/advisories/2009/2744

Share on: