Skip to main content

Vendor/product archive

itechscripts / travelon_express CVEs

Beta · best-effort

3 CVEs tagged to itechscripts / travelon_express0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2012-4281

Published Aug 13, 2012

Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2939

Published May 27, 2012

Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute arbitrary code by uploading a file with an executable exten…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2938

Published May 27, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the holiday name field to (1) holid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1