Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter.
References
Configurations
History
No history.
Information
Published : 2009-02-20 17:30
Updated : 2024-02-04 17:33
NVD link : CVE-2008-6215
Mitre link : CVE-2008-6215
CVE.ORG link : CVE-2008-6215
JSON object : View
Products Affected
bookingcentre
- booking_system_for_hotels_group
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')