Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2017-20130
Disclosure Date: July 16, 2022 (last updated February 24, 2025)
A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2019-20336
Disclosure Date: January 05, 2020 (last updated February 21, 2025)
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
0
Attacker Value
Unknown
CVE-2019-20337
Disclosure Date: April 19, 2019 (last updated February 21, 2025)
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2018-16457
Disclosure Date: October 04, 2018 (last updated February 15, 2024)
PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory.
0
Attacker Value
Unknown
CVE-2018-15187
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
0
Attacker Value
Unknown
CVE-2018-15189
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
0
Attacker Value
Unknown
CVE-2018-15188
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile.
0
Attacker Value
Unknown
CVE-2018-6796
Disclosure Date: February 07, 2018 (last updated November 26, 2024)
PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
0
Attacker Value
Unknown
CVE-2018-6364
Disclosure Date: January 29, 2018 (last updated November 26, 2024)
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
0
Attacker Value
Unknown
CVE-2018-5075
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.
0