Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown
CVE-2008-2265
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.
0
Attacker Value
Unknown
CVE-2007-6472
Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-6163
Disclosure Date: November 29, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-6169
Disclosure Date: November 29, 2007 (last updated October 04, 2023)
SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-2007-6163. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-5056
Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter.
0
Attacker Value
Unknown
CVE-2007-4834
Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/.
0
Attacker Value
Unknown
CVE-2007-0490
Disclosure Date: January 25, 2007 (last updated October 04, 2023)
index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.
0
Attacker Value
Unknown
CVE-2006-6342
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.
0
Attacker Value
Unknown
CVE-2006-5840
Disclosure Date: November 10, 2006 (last updated November 08, 2023)
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version
0
Attacker Value
Unknown
CVE-2006-3167
Disclosure Date: June 22, 2006 (last updated October 04, 2023)
Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message.
0