Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3185. PoCs published by K-159.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Relative Real Estate Systems <= 3.0 via the 'listing_id' parameter in index.php. It allows remote attackers to extract user credentials (username, password, email) from the 'realtors' and 'users' tables when magic_quotes is disabled.
Description
SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Relative Real Estate Systems <= 3.0 via the 'listing_id' parameter in index.php. It allows remote attackers to extract user credentials (username, password, email) from the 'realtors' and 'users' tables when magic_quotes is disabled.