CVE-2022-22909
- EPSS 33.1%
- Veröffentlicht 03.03.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:36
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
CVE-2021-38559
- EPSS 0.25%
- Veröffentlicht 26.08.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:26
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
CVE-2021-37833
- EPSS 6.85%
- Veröffentlicht 03.08.2021 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:56
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.
CVE-2021-37832
- EPSS 10.07%
- Veröffentlicht 03.08.2021 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:15:56
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
CVE-2019-9085
- EPSS 0.72%
- Veröffentlicht 24.06.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:50:57
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-numeric value), as demonstrated by the anno=2019&id...
CVE-2019-9087
- EPSS 0.43%
- Veröffentlicht 07.06.2019 21:29:03
- Zuletzt bearbeitet 21.11.2024 04:50:57
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
CVE-2019-9086
- EPSS 0.43%
- Veröffentlicht 07.06.2019 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:50:57
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
CVE-2019-9084
- EPSS 0.74%
- Veröffentlicht 07.06.2019 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:50:57
In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It ...
CVE-2019-8937
- EPSS 47.88%
- Veröffentlicht 17.05.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:41
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
CVE-2018-1000871
- EPSS 0.29%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack a...