CVE-2010-4737 Information

Description

SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter.

Reference

http://packetstormsecurity.org/files/view/96388/hotwebrentals-sqlpr.txt http://secunia.com/advisories/36747 http://securityreason.com/securityalert/8085 http://www.exploit-db.com/exploits/15688 http://www.securityfocus.com/bid/45184

Share on: