Back to Database
Status published
High
CVE-2009-3497
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone...
Vulnerability Description
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-3497
Credits & Attribution
No credits recorded in the NVD database.
References
More from vastal
View All →CVE-2018-6367
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone...
Critical
9.8
CVE-2017-15991
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows...
Critical
9.8
CVE-2017-15975
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the...
Critical
9.8
CVE-2015-2563
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9...
High
7.5
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3...
Medium
4.3
Affected Vendor
vastal
View all reports →Affected Software
agent zone
Vulnerable Versions:
Unknown
Timeline
Official Publish:
September 30th, 2009
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.