peter bassill · operator
$ cve CVE-2010-4738 JSON

CVE-2010-4738 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.8% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2011-02-16
Last modified2026-06-16

Affected (1)

VendorProduct
raemediareal estate single and multi agent system

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD