CVE-2015-7714

HIGH

Realtyna RPL <8.9.5 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7714. PoCs published by Bikramaditya Guha.

AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Realtyna RPL 8.9.2 Joomla extension. It provides specific POST parameters and payloads to manipulate SQL queries by injecting arbitrary SQL code.

Description

Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bikramaditya Guha · textwebappsphp
https://www.exploit-db.com/exploits/38527

This exploit demonstrates multiple SQL injection vulnerabilities in Realtyna RPL 8.9.2 Joomla extension. It provides specific POST parameters and payloads to manipulate SQL queries by injecting arbitrary SQL code.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Realtyna RPL 8.9.2 Joomla Extension
Auth required
Prerequisites: Access to the target Joomla administrator interface · Valid authentication credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38527/
Vendor Advisory x_refsource_confirm
http://rpl.realtyna.com/change-logs/rpl7-changelog

Scores

CVSS v3 7.2
EPSS 0.0219
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
realtyna/realtyna_property_listing < 8.9.5
Published Oct 18, 2017
Tracked Since Feb 18, 2026