CVE-2012-2740: SQL Injection
Published Sep 6, 2012
·Updated
SQL injection vulnerability in publichtml/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action.
Affected Software
16 affected components
PHPlist PHPList<=2.10.17
PHPlist PHPList=2.10.1
PHPlist PHPList=2.10.2
PHPlist PHPList=2.10.3
PHPlist PHPList=2.10.4
PHPlist PHPList=2.10.5
PHPlist PHPList=2.10.7
PHPlist PHPList=2.10.8
PHPlist PHPList=2.10.9
PHPlist PHPList=2.10.10
PHPlist PHPList=2.10.11
PHPlist PHPList=2.10.12
PHPlist PHPList=2.10.13
PHPlist PHPList=2.10.14
PHPlist PHPList=2.10.15
PHPlist PHPList=2.10.16
Remediation
Patch Available
Event History
Sep 6, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2740?
CVE-2012-2740 has been classified as a medium severity SQL injection vulnerability in phpList.
2
How do I fix CVE-2012-2740?
To fix CVE-2012-2740, upgrade phpList to version 2.10.18 or later.
3
What impact does CVE-2012-2740 have on phpList installations?
CVE-2012-2740 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
4
Which versions of phpList are affected by CVE-2012-2740?
CVE-2012-2740 affects phpList versions prior to 2.10.18, including 2.10.1 through 2.10.16.
5
Is there an exploit for CVE-2012-2740?
Yes, there are known exploits for CVE-2012-2740 that demonstrate the SQL injection vulnerability.