CVE-2009-4600 Information

Description

SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.

Reference

http://osvdb.org/60866 http://secunia.com/advisories/37633 http://www.exploit-db.com/exploits/10361 http://www.securityfocus.com/bid/37265 https://exchange.xforce.ibmcloud.com/vulnerabilities/54647

Share on: