CVE-2012-3953
published 2012-08-12CVE-2012-3953: SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
1.12%
62.2th percentile
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phplist | phplist | <= 2.10.18 | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
| phplist | phplist | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
http://archives.neohapsis.com/archives/bugtraq/2012-08/0059.htmlhttp://osvdb.org/84483http://www.phplist.com/?lid=579https://exchange.xforce.ibmcloud.com/vulnerabilities/77527https://www.htbridge.com/advisory/HTB23100http://archives.neohapsis.com/archives/bugtraq/2012-08/0059.htmlhttp://osvdb.org/84483http://www.phplist.com/?lid=579https://exchange.xforce.ibmcloud.com/vulnerabilities/77527https://www.htbridge.com/advisory/HTB23100
2012-08-12
Published