CVE Alert: CVE-2015-20118 - Next Click Ventures - RealtyScript - RedPacket Security

Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations interface.

RedPacket Security
CVE Alert: CVE-2015-20115 - Next Click Ventures - RealtyScript - RedPacket Security

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter

RedPacket Security
CVE Alert: CVE-2015-20120 - Next Click Ventures - RealtyScript - RedPacket Security

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract

RedPacket Security