Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2025-1515
Disclosure Date: March 05, 2025 (last updated March 05, 2025)
The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn login request process. This makes it possible for unauthenticated attackers to bypass official authentication and log in as any user on the site, including administrators.
0
Attacker Value
Unknown
CVE-2025-22645
Disclosure Date: February 18, 2025 (last updated February 27, 2025)
Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager allows Password Brute Forcing. This issue affects Real Estate Manager: from n/a through 7.3.
0
Attacker Value
Unknown
CVE-2024-6415
Disclosure Date: June 30, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of the component New Widget Handler. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270001 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-4239
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7.1 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.
0
Attacker Value
Unknown
CVE-2010-5013
Disclosure Date: November 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.
0
Attacker Value
Unknown
CVE-2009-4318
Disclosure Date: December 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-4674
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.
0
Attacker Value
Unknown
CVE-2006-5934
Disclosure Date: November 16, 2006 (last updated October 04, 2023)
SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.
0
Attacker Value
Unknown
CVE-2006-0624
Disclosure Date: February 09, 2006 (last updated February 22, 2025)
SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
0