CVE-2012-5290

EasyWebRealEstate - SQL Injection via lstid or infoid Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72148

Scores

EPSS 0.0123
EPSS Percentile 65.8%

Details

CWE
CWE-89
Status published
Products (1)
wcs4web/easywebrealestate
Published Oct 04, 2012
Tracked Since Feb 18, 2026