{"api_version":"1","generated_at":"2026-07-23T05:24:41+00:00","cve":"CVE-2008-5772","urls":{"html":"https://cve.report/CVE-2008-5772","api":"https://cve.report/api/cve/CVE-2008-5772.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5772","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5772"},"summary":{"title":"CVE-2008-5772","description":"Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-12-30 20:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securityreason.com/securityalert/4848","name":"http://securityreason.com/securityalert/4848","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASPSiteWare RealtyListing V1/V2 SQL Injection Vulnerabilities - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/7464","name":"https://www.exploit-db.com/exploits/7464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASPSiteWare RealtyListing V1/V2 SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/50708","name":"http://osvdb.org/50708","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/32812","name":"http://www.securityfocus.com/bid/32812","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple ASP SiteWare Products SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/50707","name":"http://osvdb.org/50707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47323","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47323","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33167","name":"http://secunia.com/advisories/33167","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"RealtyListings Multiple SQL Injection Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5772","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5772","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5772","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aspsiteware","cpe5":"realtylistings","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5772","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aspsiteware","cpe5":"realtylistings","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:04:44.492Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"50708","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/50708"},{"name":"4848","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4848"},{"name":"7464","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/7464"},{"name":"50707","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/50707"},{"name":"32812","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32812"},{"name":"realtylisting-typedetail-sql-injection(47323)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47323"},{"name":"33167","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33167"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"50708","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/50708"},{"name":"4848","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4848"},{"name":"7464","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/7464"},{"name":"50707","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/50707"},{"name":"32812","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32812"},{"name":"realtylisting-typedetail-sql-injection(47323)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47323"},{"name":"33167","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33167"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5772","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"50708","refsource":"OSVDB","url":"http://osvdb.org/50708"},{"name":"4848","refsource":"SREASON","url":"http://securityreason.com/securityalert/4848"},{"name":"7464","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/7464"},{"name":"50707","refsource":"OSVDB","url":"http://osvdb.org/50707"},{"name":"32812","refsource":"BID","url":"http://www.securityfocus.com/bid/32812"},{"name":"realtylisting-typedetail-sql-injection(47323)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/47323"},{"name":"33167","refsource":"SECUNIA","url":"http://secunia.com/advisories/33167"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5772","datePublished":"2008-12-30T20:00:00.000Z","dateReserved":"2008-12-30T00:00:00.000Z","dateUpdated":"2024-08-07T11:04:44.492Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-30 20:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aspsiteware:realtylistings:1.0:*:*:*:*:*:*:*","matchCriteriaId":"93082583-F3ED-4424-966F-D3FFBA52A900"},{"vulnerable":true,"criteria":"cpe:2.3:a:aspsiteware:realtylistings:2.0:*:*:*:*:*:*:*","matchCriteriaId":"12EB8C10-8D68-4177-83B7-0EB26726F6CD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5772","Ordinal":"1","Title":"CVE-2008-5772","CVE":"CVE-2008-5772","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5772","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.","Type":"Description","Title":"CVE-2008-5772"},{"CveYear":"2008","CveId":"5772","Ordinal":"2","NoteData":"2008-12-30","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5772","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}