CVE-2012-2937: SQL Injection
Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/adminindex.php, (2) display parameter in a minimize action to admin/adminindex.php, (3) enabled[] parameter to admin/adminusers.php, or (4) msgid to the module.php in the simplemessaging module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2937?
CVE-2012-2937 is considered to have a high severity level due to its potential for remote SQL injection attacks.
How do I fix CVE-2012-2937?
To fix CVE-2012-2937, upgrade Pligg CMS to version 1.2.2 or later to mitigate the SQL injection vulnerabilities.
What are the impacts of CVE-2012-2937?
The impacts of CVE-2012-2937 can include unauthorized access to the database and manipulation of data through SQL injection.
Which versions of Pligg CMS are affected by CVE-2012-2937?
CVE-2012-2937 affects all versions of Pligg CMS before 1.2.2, including versions 1.0.0 to 1.2.1.
Can I exploit CVE-2012-2937 to gain access to the website?
Yes, an attacker can exploit CVE-2012-2937 to execute arbitrary SQL commands and potentially gain unauthorized access to the website's data.