Show filters
110 Total Results
Displaying 71-80 of 110
Sort by:
Attacker Value
Unknown
CVE-2010-3607
Disclosure Date: September 24, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2010-3606
Disclosure Date: September 24, 2010 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
0
Attacker Value
Unknown
CVE-2010-1654
Disclosure Date: May 03, 2010 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-1062
Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-1063
Disclosure Date: March 23, 2010 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php, and (3) staff/app/common.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-4613
Disclosure Date: January 14, 2010 (last updated October 04, 2023)
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-4600
Disclosure Date: January 12, 2010 (last updated October 04, 2023)
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-4477
Disclosure Date: December 30, 2009 (last updated October 04, 2023)
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
0
Attacker Value
Unknown
CVE-2009-4478
Disclosure Date: December 30, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html.
0
Attacker Value
Unknown
CVE-2009-4318
Disclosure Date: December 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.
0