Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/27253http://pridels0.blogspot.com/2006/06/free-realty-vuln.html