PT-2011-4428 · Myre · Myre Real Estate

Sooraj K.S

·

Published

2011-09-15

·

Updated

2012-02-14

·

CVE-2011-3394

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MYRE Real Estate Software (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting a SQL injection vulnerability in the findagent.php file via the page parameter in the API endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3394

Affected Products

Myre Real Estate