CVE-2012-4686: SQL Injection
SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4686?
CVE-2012-4686 is classified as a critical severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2012-4686?
To fix CVE-2012-4686, upgrade to vBulletin version 4.1.11 or later, which addresses the SQL injection vulnerability.
What impact does CVE-2012-4686 have on my system?
CVE-2012-4686 can potentially compromise your database and allow unauthorized access to sensitive information.
What is the nature of the vulnerability in CVE-2012-4686?
CVE-2012-4686 is an SQL injection vulnerability caused by inadequate input validation of the announcementid parameter.
Who is affected by CVE-2012-4686?
Any installation of vBulletin version 4.1.10 is affected by CVE-2012-4686, making it vulnerable to SQL injection attacks.