1 results (0.040 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2

Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. Advanced Real Estate Script 4.0.7 tiene una inyección SQL mediante los parámetros Projectmain, proj_type, searchtext, sell_price o maxprice en search-results.php. • https://www.exploit-db.com/exploits/43304 https://packetstormsecurity.com/files/145345/Advanced-Real-Estate-Script-4.0.7-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •