CVE-2012-4258

Myrephp Myre Real Estate Software - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/19132
exploitdb WORKING POC VERIFIED
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/18843

References (4)

Core 4

Scores

EPSS 0.0149
EPSS Percentile 81.1%

Details

CWE
CWE-89
Status published
Products (1)
myrephp/myre_real_estate_software 2012 q2
Published Aug 13, 2012
Tracked Since Feb 18, 2026