Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2008-2265

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.
0
Attacker Value
Unknown

CVE-2007-6472

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-6163

Disclosure Date: November 29, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-6169

Disclosure Date: November 29, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-2007-6163. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-5056

Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.
0
Attacker Value
Unknown

CVE-2007-4834

Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.
0
Attacker Value
Unknown

CVE-2007-0490

Disclosure Date: January 25, 2007 (last updated October 04, 2023)
index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.
0
Attacker Value
Unknown

CVE-2006-6342

Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.
0
Attacker Value
Unknown

CVE-2006-5840

Disclosure Date: November 10, 2006 (last updated November 08, 2023)
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version
0
Attacker Value
Unknown

CVE-2006-3167

Disclosure Date: June 22, 2006 (last updated October 04, 2023)
Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message.
0