32134vdb entry
http://www.securityfocus.com/bid/32134 CVE-2008-6798
Pre Real Estate Listings - Arbitrary File Upload
Record summary
CVE-2008-6798 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPre Real Estate Listings - Arbitrary File UploadExploitDB exploitby BackDoorNot analyzed1 file
References
4ADV-2008-3121vdb entry
http://www.vupen.com/english/advisories/2008/3121 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6798 7094exploit
https://www.exploit-db.com/exploits/7094