SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Free_realty | Free_realty | * | 2.9_0.7 (including) |