CVE-2008-3861 Information

Description

Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.

Reference

http://secunia.com/advisories/31613 http://securityreason.com/securityalert/4198 http://www.securityfocus.com/bid/30862 https://exchange.xforce.ibmcloud.com/vulnerabilities/44720 https://www.exploit-db.com/exploits/6320

Share on: