CVE-2008-2881
Relative Real Estate Systems < 3.0 - Cleartext Password Storage
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2881. PoCs published by K-159.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Relative Real Estate Systems <= 3.0 via the 'listing_id' parameter in index.php. It allows remote attackers to extract user credentials (username, password, email) from the 'realtors' and 'users' tables when magic_quotes is disabled.
Description
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Relative Real Estate Systems <= 3.0 via the 'listing_id' parameter in index.php. It allows remote attackers to extract user credentials (username, password, email) from the 'realtors' and 'users' tables when magic_quotes is disabled.