CVE-2005-4018

Landshop Real Estate Commerce System < 0.6.3 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26720

Scores

EPSS 0.0056
EPSS Percentile 67.8%

Classification

Status draft

Affected Products (1)

landshop/real_estate_commerce_system < 0.6.3

Timeline

Published Dec 05, 2005
Tracked Since Feb 18, 2026