Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 19 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextclickventures
Nextclickventures realtyscript |
|
| CPEs | cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextclickventures
Nextclickventures realtyscript |
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Next Click Ventures
Next Click Ventures realtyscript |
|
| Vendors & Products |
Next Click Ventures
Next Click Ventures realtyscript |
Sun, 15 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by character based on response timing differences. | |
| Title | RealtyScript 4.0.2 Multiple Time-based Blind SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:20:17.335Z
Reserved: 2026-03-15T18:07:08.695Z
Link: CVE-2015-20120
Updated: 2026-03-16T14:17:07.956Z
Status : Analyzed
Published: 2026-03-16T14:17:47.957
Modified: 2026-03-19T14:15:53.783
Link: CVE-2015-20120
No data.
OpenCVE Enrichment
Updated: 2026-03-23T14:01:18Z