PT-2011-5123 · Vik Realty · Com Vikrealestate

Chris Russell

·

Published

2011-12-15

·

Updated

2012-02-09

·

CVE-2011-4823

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions com vikrealestate version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the contract parameter in a results action and the imm parameter in a show action to "index.php".
Recommendations For version 1.0, consider restricting access to the vulnerable parameters contract and imm in the respective actions until a patch is available. Avoid using the contract parameter in the results action and the imm parameter in the show action to "index.php" until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4823

Affected Products

Com Vikrealestate