A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
{ "binaries": [ { "binary_name": "hoteldruid", "binary_version": "2.1.4-1ubuntu2" } ] }
{ "binaries": [ { "binary_name": "hoteldruid", "binary_version": "2.2.2-1" } ] }
{ "binaries": [ { "binary_name": "hoteldruid", "binary_version": "3.0.1-1" } ] }
{ "binaries": [ { "binary_name": "hoteldruid", "binary_version": "3.0.3-1" } ] }
{ "binaries": [ { "binary_name": "hoteldruid", "binary_version": "3.0.6-1" } ] }