CVE-2015-20121 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting a…
High CVSS: 8.8

CVE-2015-20121

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based blind SQL injection techniques to extract sensitive database information or cause denial of service through sleep-based payloads.
Vendor
Nextclickventures
Product
Realtyscript
CWE
CWE-89
Yayın Tarihi
2026-03-16 14:17:48
Güncelleme
2026-03-18 15:24:32
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar