PT-2013-2040 · Myre · Myre Vacation Rental

D3B4G

·

Published

2013-08-25

·

Updated

2013-08-27

·

CVE-2012-6586

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MYRE Vacation Rental Software (affected versions not specified)
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This can be achieved through specific parameters in certain API endpoints, such as the garage1 or bathrooms1 parameter to "vacation/1 mobile/search.php", or through unspecified input to "vacation/widgate/request more information.php".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6586

Affected Products

Myre Vacation Rental