RSS   Vulnerabilities for 'Free realty'   RSS

2006-06-22
 
CVE-2006-3167

 

 
Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message.

 
 
CVE-2006-3166

 

 
Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.

 
 
CVE-2006-3165

 

 
SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top