
CVE-2015-7714 – Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections
https://notcve.org/view.php?id=CVE-2015-7714
23 Oct 2015 — Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php. Múltiples inyecciones SQL en el componente Realtyna RPL (com_rpl) en versiones anteriores a la 8.9.5 para Joomla! permiten que administradore... • https://packetstorm.news/files/id/134066 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-7715 – Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2015-7715
23 Oct 2015 — Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el componente Realtyna RPL (com_rpl) en versiones anteriores a la 8.9.5 para Joomla! permite que atacantes remotos secuestren la autenticación de administradores para peticiones que añadan un u... • https://packetstorm.news/files/id/134067 • CWE-352: Cross-Site Request Forgery (CSRF) •