CVE-2018-5072
https://notcve.org/view.php?id=CVE-2018-5072
Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter. Online Ticket Booking tiene Cross-Site Scripting (XSS) mediante el parámetro keyword en admin/sitesettings.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Advanced%20Real%20Estate%20Script.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-5077
https://notcve.org/view.php?id=CVE-2018-5077
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter. Online Ticket Booking tiene Cross-Site Scripting (XSS) mediante el parámetro moviename en admin/movieedit.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/Advanced%20Real%20Estate%20Script.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-17603 – Advanced Real Estate Script 4.0.7 - SQL Injection
https://notcve.org/view.php?id=CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. Advanced Real Estate Script 4.0.7 tiene una inyección SQL mediante los parámetros Projectmain, proj_type, searchtext, sell_price o maxprice en search-results.php. • https://www.exploit-db.com/exploits/43304 https://packetstormsecurity.com/files/145345/Advanced-Real-Estate-Script-4.0.7-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •