CVE-2012-4279: Rwcinc Free Realty

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to agentdisplay.php or (2) edit parameter to admin/admin.php.

Affected products

  • Rwcinc Free Realty: version 3.1-0.6 only

Published 2012-08-13. Last modified 2026-06-16.