RSS   Vulnerabilities for 'Pre real estate listings'   RSS

2009-08-24
 
CVE-2008-7052

 

 
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.

 
2009-05-07
 
CVE-2008-6798

CWE-89
 

 
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

 
 
CVE-2008-6796

 

 
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).

 
2008-09-23
 
CVE-2008-4177

CWE-89
 

 
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.

 

 >>> Vendor: Preprojects 14 Products
Pre shopping mall
E-smart cart
Php jobwebsite pro
Pre job board
Pre ads portal
Pre real estate listings
Pre e-learning portal
Pre resume submitter
Pre classified listings
Pre podcast portal
Pre classified listings asp
Pre online tests generator
Business cards designer
Pre printing press


Copyright 2024, cxsecurity.com

 

Back to Top