Advanced Real Estate Script Project's vulnerability profile concentrates in its real-estate web application product and reflects the characteristic input-handling and access-control weaknesses of server-side web software: cross-site scripting, SQL injection, CSRF, and memory-safety issues recur across disclosures. A meaningful share of the vulnerabilities reach serious severity, and public exploit code has emerged for some flaws, underscoring the need for defenders deploying this software to prioritize patching and input-validation hardening. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advanced Real Estate Script Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17603CRITICAL Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | Dec 13, 2017 | 9.8 | 42 | NO | YES |
CVE-2018-15187HIGH PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. | Aug 10, 2018 | 8.0 | 25 | NO | NO |
CVE-2019-20337HIGH In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection. | Jan 5, 2020 | 7.2 | 23 | NO | NO |
CVE-2018-15188MEDIUM PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a pro | Aug 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2019-20336MEDIUM In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS. | Jan 5, 2020 | 6.1 | 21 | NO | NO |
CVE-2018-5073MEDIUM Online Ticket Booking has CSRF via admin/movieedit.php. | Jan 3, 2018 | 6.8 | 21 | NO | NO |
CVE-2018-15189MEDIUM PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile. | Aug 10, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-5072MEDIUM Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter. | Jan 3, 2018 | 4.8 | 18 | NO | NO |
CVE-2018-5078MEDIUM Online Ticket Booking has XSS via the admin/eventlist.php cast parameter. | Jan 3, 2018 | 4.8 | 17 | NO | NO |
CVE-2018-5077MEDIUM Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter. | Jan 3, 2018 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advanced Real Estate Script Project.
Media articles that mention a CVE ID that affects a product developed by Advanced Real Estate Script Project — matched by CVE ID, not by vendor name.