VYPR
Unrated severityNVD Advisory· Published Aug 29, 2008· Updated Apr 23, 2026

CVE-2008-3861

CVE-2008-3861

Description

Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.

Affected products

10
  • cpe:2.3:a:phpmyrealty:phpmyrealty:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:phpmyrealty:phpmyrealty:*:*:*:*:*:*:*:*range: <=1.0.9
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:phpmyrealty:phpmyrealty:1.0.8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.