Home→Descriptions→SA49118
| Secunia ID | |
| CVE-ID | |
| Release Date |
14 May 2012 |
| Last Change |
14 Aug 2012 |
| Criticality | |
| Solution Status |
Unpatched |
| Software |
Travelon Express 6.x |
| Where | |
| Impact |
Manipulation of dataThis includes vulnerabilities where a user or a remote attacker can manipulate local data on a system, but not necessarily be able to gain escalated privileges or system access. The most frequent type of vulnerabilities with this impact are SQL-injection vulnerabilities, where a malicious user or person can manipulate SQL queries. |
| Description |
Two vulnerabilities have been reported in Travelon Express, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the "hid" parameter to holiday.php and holiday_book.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerabilities are reported in version 6.2. Other versions may also be affected. |
| Solution |
Filter malicious characters and character sequences using a proxy. |
| Reported by |
the_storm via Vulnerability Research Laboratory |
| Original Advisory |