Vulnerabilities > Netartmedia > Real Estate Portal

DATE CVE VULNERABILITY TITLE RISK
2010-09-24 CVE-2010-3607 Cross-Site Scripting vulnerability in Netartmedia Real Estate Portal 2.0
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
4.3
2010-09-24 CVE-2010-3606 Path Traversal vulnerability in Netartmedia Real Estate Portal 2.0
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
6.8
2010-01-14 CVE-2009-4613 SQL Injection vulnerability in Netartmedia Real Estate Portal 2.0
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter.
network
low complexity
netartmedia CWE-89
7.5
2009-02-03 CVE-2008-6042 SQL Injection vulnerability in Netartmedia Real Estate Portal 2.0
SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.
network
low complexity
netartmedia CWE-89
7.5