CVE-2012-2332: SQL Injection
SQL injection vulnerability in serendipity/serendipityadmin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugintoconf] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2332?
The severity of CVE-2012-2332 is considered medium as it allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2012-2332?
To fix CVE-2012-2332, update Serendipity to version 1.6.1 or later, which addresses this vulnerability.
What versions of Serendipity are affected by CVE-2012-2332?
CVE-2012-2332 affects all versions of Serendipity prior to 1.6.1.
Can CVE-2012-2332 lead to data exposure?
Yes, CVE-2012-2332 can lead to unauthorized access and manipulation of the database, resulting in potential data exposure.
Is CVE-2012-2332 related to CSRF attacks?
Yes, CVE-2012-2332 may be the result of cross-site request forgery (CSRF) issues that allow malicious SQL injection.