Lucene search

K
cveMitreCVE-2009-3357
HistorySep 24, 2009 - 4:30 p.m.

CVE-2009-3357

2009-09-2416:30:02
CWE-89
mitre
web.nvd.nist.gov
29
cve
2009
3357
sql injection
hotel booking reservation system
joomla

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.002

Percentile

58.6%

Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) h_id, (2) id, and (3) rid parameters to longDesc.php, and the h_id parameter to (4) detail.php, (5) detail1.php, (6) detail2.php, (7) detail3.php, (8) detail4.php, (9) detail5.php, (10) detail6.php, (11) detail7.php, and (12) detail8.php, different vectors than CVE-2008-5865, CVE-2008-5874, and CVE-2008-5875.

Affected configurations

Nvd
Node
joomlajoomla
AND
joomlahbscom_hbssearch
VendorProductVersionCPE
joomlajoomla*cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*
joomlahbscom_hbssearch*cpe:2.3:a:joomlahbs:com_hbssearch:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.002

Percentile

58.6%

Related for CVE-2009-3357