CVE-2012-4281 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_book.php (3) id parameter to pages.php (4) fid parameter to admin/airline-edit.php or (5) cid parameter to admin/customer-edit.php.
Reference
http://secunia.com/advisories/49118 http://www.exploit-db.com/exploits/18871 http://www.osvdb.org/81882 http://www.osvdb.org/81883 http://www.osvdb.org/81884 http://www.osvdb.org/81885 http://www.osvdb.org/81886 http://www.securityfocus.com/bid/53500 http://www.vulnerability-lab.com/get_content.php?id=530 https://exchange.xforce.ibmcloud.com/vulnerabilities/75540
Share on: