Vulnerabilities > SG Real Estate Portal

DATE CVE VULNERABILITY TITLE RISK
2009-01-30 CVE-2008-6011 SQL Injection vulnerability in SG Real Estate Portal SG Real Estate Portal 2.0
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
network
low complexity
sg-real-estate-portal CWE-89
7.5
2009-01-30 CVE-2008-6010 Path Traversal vulnerability in SG Real Estate Portal SG Real Estate Portal 2.0
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a ..
network
low complexity
sg-real-estate-portal CWE-22
5.0
2009-01-30 CVE-2008-6009 Improper Authentication vulnerability in SG Real Estate Portal SG Real Estate Portal 2.0
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
network
low complexity
sg-real-estate-portal CWE-287
7.5