CVE-2010-4738
Summary
| CVE | CVE-2010-4738 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-16 03:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Raemedia | Real Estate Single And Multi Agent System | 3.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Real Estate Single 'resulttype.asp' SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Multi Agent System 'city.asp' SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Rae Media INC Real Estate Single and Multi Agent System SQL Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | Exploit |
| Rae Media INC Real Estate Single and Multi Agent System SQL Injection - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Rae Media Inc Real Estate Single / Multi Agent Listing System SQL Injection - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Rae Media Real Estate Single Agent SQL Injection Vulnerability - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Rae Media Real Estate Multi Agent SQL Injection Vulnerability - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| osvdb.org/69628 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/69627 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.