MYREphp Vacation Rental Software Cross Site Scripting and SQL Injection Vulnerabilities
4 Dec. 2012
Summary
MYREphp Vacation Rental Software is prone to a cross-site scripting vulnerability and multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Myrephp Vacation Rental is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the search.php and request_more_information.php scripts using the bathrooms1 and garage1 parameters, which could allow the attacker to view, add, modify or delete information in the back-end database.