First published: Thu Jun 22 2006(Updated: )
SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Realty | =2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3148 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2006-3148, upgrade Open-Realty to a version that is not affected by this SQL injection vulnerability.
CVE-2006-3148 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
CVE-2006-3148 is found in Open-Realty version 2.3.1.
CVE-2006-3148 involves the 'sorttype' parameter in the index.php file.