CVE-2012-3953
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
- Affected products
- Phplist
- Phplist
- ≤ 2.10.18, 2.6.5, 2.7.1, 2.7.2, 2.8.2, 2.8.7, 2.8.12, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 2.10.7, 2.10.8, 2.10.9, 2.10.10, 2.10.11, 2.10.12, 2.10.13, 2.10.14, 2.10.15, 2.10.16, 2.10.17
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2012-08-12
CVE-2012-3953 at NVD
3 known exploits for CVE-2012-3953
Proof-of-concept code and exploit modules indexed by Sploitus