Record summary

CVE-2007-6472 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHPMyRealty 1.0.x - 'search.php' SQL InjectionExploitDB exploitby KollerNot analyzed1 file
ExploitDB

PoC details

References

7