ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-25316
+3 in the same advisory: …25315 …25314 …25318
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • hotel management system project hotel management system
CVE-2023-34487
+1 in the same advisory: …34486
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection.

itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • online hotel management system project online hotel management system
CVE-2022-48090
+1 in the same advisory: …48091
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.

Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • hotel management system project hotel management system
CVE-2022-36254
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary

Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".

NVD description · AI analysis pending
5.4<1% PoC
  • hotel management system project hotel management system
CVE-2022-2291
+1 in the same advisory: …2292
A vulnerability was found in SourceCodester Hotel Management System 2.0.

A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.4<1% PoC
  • hotel management system project hotel management system
CVE-2022-28110
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

NVD description · AI analysis pending
9.8<1%
  • hotel management system project hotel management system
CVE-2022-27475
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.

NVD description · AI analysis pending
6.1<1%
  • hotel management system project hotel management system
CVE-2021-41651
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system.

A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

NVD description · AI analysis pending
7.52% PoC
  • hotel management system project hotel management system