SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Real_estate_commerce_system | Landshop | * | 0.6.3 (including) |