CVE-2010-4738 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.8% (pctl 78)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.8% — more likely to be exploited than 78% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-02-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| raemedia | real estate single and multi agent system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Rae Media Real Estate Single Agent - SQL Injection | 2011-02-16 |
| exploit-db | Rae Media Real Estate Multi Agent - SQL Injection | 2011-02-16 |
References
- http://osvdb.org/69627
- http://osvdb.org/69628
- http://packetstormsecurity.org/files/view/96389/raemediaincresmas-sql.txt
- http://secunia.com/advisories/42515
- http://securityreason.com/securityalert/8080
- http://securityreason.com/securityalert/8082
- http://securityreason.com/securityalert/8088
- http://www.securityfocus.com/bid/45211
- http://www.securityfocus.com/bid/45212
- http://osvdb.org/69627
- http://osvdb.org/69628
- http://packetstormsecurity.org/files/view/96389/raemediaincresmas-sql.txt
- http://secunia.com/advisories/42515
- http://securityreason.com/securityalert/8080
- http://securityreason.com/securityalert/8082
- http://securityreason.com/securityalert/8088
- http://www.securityfocus.com/bid/45211
- http://www.securityfocus.com/bid/45212
→ the Explorer · watch your stack · NVD