CVE-2010-4738 Information

Description

Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.

Reference

http://osvdb.org/69627 http://osvdb.org/69628 http://packetstormsecurity.org/files/view/96389/raemediaincresmas-sql.txt http://secunia.com/advisories/42515 http://securityreason.com/securityalert/8080 http://securityreason.com/securityalert/8082 http://securityreason.com/securityalert/8088 http://www.securityfocus.com/bid/45211 http://www.securityfocus.com/bid/45212

Share on: