Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2022-31574

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2017-17909

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
0
Attacker Value
Unknown

CVE-2017-17908

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
0
Attacker Value
Unknown

CVE-2017-17591

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
0
Attacker Value
Unknown

CVE-2017-17628

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
0
Attacker Value
Unknown

CVE-2012-5290

Disclosure Date: October 04, 2012 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php.
0
Attacker Value
Unknown

CVE-2011-4823

Disclosure Date: December 15, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.
0
Attacker Value
Unknown

CVE-2010-2357

Disclosure Date: June 21, 2010 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-2635

Disclosure Date: July 28, 2009 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2006-5886

Disclosure Date: November 14, 2006 (last updated October 04, 2023)
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.
0