CVE-2012-3953: SQL Injection
Published Aug 12, 2012
·Updated
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
Affected Software
23 affected components
PHPlist PHPList<=2.10.18
PHPlist PHPList=2.6.5
PHPlist PHPList=2.7.1
PHPlist PHPList=2.7.2
PHPlist PHPList=2.8.2
PHPlist PHPList=2.8.7
PHPlist PHPList=2.8.12
PHPlist PHPList=2.10.1
PHPlist PHPList=2.10.2
PHPlist PHPList=2.10.3
PHPlist PHPList=2.10.4
PHPlist PHPList=2.10.5
PHPlist PHPList=2.10.7
PHPlist PHPList=2.10.8
PHPlist PHPList=2.10.9
PHPlist PHPList=2.10.10
PHPlist PHPList=2.10.11
PHPlist PHPList=2.10.12
PHPlist PHPList=2.10.13
PHPlist PHPList=2.10.14
PHPlist PHPList=2.10.15
PHPlist PHPList=2.10.16
PHPlist PHPList=2.10.17
Remediation
Patch Available
Event History
Aug 12, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3953?
CVE-2012-3953 is considered a moderate severity vulnerability due to its potential to allow arbitrary SQL command execution.
2
How do I fix CVE-2012-3953?
To fix CVE-2012-3953, upgrade your phpList installation to version 2.10.19 or later.
3
Which versions of phpList are affected by CVE-2012-3953?
CVE-2012-3953 affects phpList versions prior to 2.10.19, including specific versions like 2.10.1 through 2.10.18 and 2.6.5 to 2.8.12.
4
Can CVE-2012-3953 be exploited remotely?
Yes, CVE-2012-3953 can be exploited remotely by sending specially crafted requests to the affected phpList application.
5
What type of vulnerability is CVE-2012-3953?
CVE-2012-3953 is classified as an SQL injection vulnerability.