Js Multi Hotel [js-multihotel] < 2.2.2
unknownThis plugins is prone to a remote file inclusion vulnerability via includes/show_image.php file parameter. Update the plugin.
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- May 15, 2015
plugin
12 known security issues reported for the Js Multihotel WordPress plugin. Most recent disclosed May 15, 2015.
Running Js Multihotel on your site? Check whether your installed version is affected.
Scan your site freeThis plugins is prone to a remote file inclusion vulnerability via includes/show_image.php file parameter. Update the plugin.
This plugin is prone to a full path disclosure vulnerability in includes/timthumb.php src parameter. Update the plugin.
[en] Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
[en] The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7) p...
[en] Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter.
Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7) phpthu...
The JS Multi Hotel Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
The JS Multi Hotel Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘path’ parameter in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter.
The js-multihotel WordPress plugin was affected by an includes/show_image.php file Parameter Remote File Inclusion DoS security vulnerability.
The js-multihotel WordPress plugin was affected by an includes/timthumb.php src Parameter Direct Request Path Disclosure security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free