CVE-2012-4279
Free Realty 3.1-0.6 - SQL Injection via Agent Display or Admin Edit Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4279. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This is a detailed vulnerability writeup for CVE-2012-4280, describing multiple web vulnerabilities in Free Reality v3.1-0.6, including SQL injection, persistent XSS, and CSRF. It includes proof-of-concept examples for each vulnerability type.
Description
Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to agentdisplay.php or (2) edit parameter to admin/admin.php.
Exploits (1)
This is a detailed vulnerability writeup for CVE-2012-4280, describing multiple web vulnerabilities in Free Reality v3.1-0.6, including SQL injection, persistent XSS, and CSRF. It includes proof-of-concept examples for each vulnerability type.