CVE-2011-3393
MYRE Real Estate Software - Cross-Site Scripting via findagent.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-3393.
AI-analyzed exploit summary The document details multiple XSS and SQL injection vulnerabilities in MYRE Real Estate Software, specifically in the 'findagent.php' file. It provides proof-of-concept URLs demonstrating the vulnerabilities but does not include functional exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter.
Exploits (1)
The document details multiple XSS and SQL injection vulnerabilities in MYRE Real Estate Software, specifically in the 'findagent.php' file. It provides proof-of-concept URLs demonstrating the vulnerabilities but does not include functional exploit code.