28155Third-party advisory
http://secunia.com/advisories/28155 CVE-2007-6472
PHPMyRealty 1.0.x - 'search.php' SQL Injection
Record summary
CVE-2007-6472 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHPMyRealty 1.0.x - 'search.php' SQL InjectionExploitDB exploitby KollerNot analyzed1 file
References
739267vdb entry
http://www.osvdb.org/39267 26932vdb entry
http://www.securityfocus.com/bid/26932 phpmyrealty-search-sql-injection(39121)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39121 phpmyrealty-findlistings-sql-injection(39122)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39122 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6472 4750exploit
https://www.exploit-db.com/exploits/4750