CVE-2015-20121Disclosure(nextclickventures / realtyscript)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based blind SQL injection techniques to extract sensitive database information or cause denial of service through sleep-based payloads.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • realtyscript

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
realtyscript

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Technical Details · 2026-03-16: 103-1603-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2015-20121 Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitra… https://www.cve.org/CVERecord?id=CVE-2015-20121

    Post summary

    The CVE refers to an SQL injection flaw in RealtyScript 4.0.2 that lets unauthenticated attackers alter database queries; no PoC, exploit, patch, or active exploitation details are provided.

    00010137
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2015-20121 - Next Click Ventures - RealtyScripts - https://www.redpacketsecurity.com/cve-alert-cve-2015-20121-next-click-ventures-realtyscripts/ #OSINT #ThreatIntel #CyberSecurity #cve-2015-20121 #next-click-ventures #realtyscripts

    Post summary

    A CVE alert for CVE‑2015‑20121 involving Next Click Ventures RealtyScripts is posted, but the brief text lacks technical specifics, PoC, or exploit information.

    0000057
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnextclickventuresrealtyscript4.0.2--

Explore more