CVE-2007-6472
N/A
N/A
Summary
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39122
- http://www.osvdb.org/39267
- https://www.exploit-db.com/exploits/4750
- http://www.securityfocus.com/bid/26932
- http://secunia.com/advisories/28155
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39121
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39122
- http://www.osvdb.org/39267
- https://www.exploit-db.com/exploits/4750
- http://www.securityfocus.com/bid/26932
- http://secunia.com/advisories/28155
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39121
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.