First published: Tue Aug 28 2012(Updated: )
SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin | =4.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4686 is classified as a critical severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2012-4686, upgrade to vBulletin version 4.1.11 or later, which addresses the SQL injection vulnerability.
CVE-2012-4686 can potentially compromise your database and allow unauthorized access to sensitive information.
CVE-2012-4686 is an SQL injection vulnerability caused by inadequate input validation of the announcementid parameter.
Any installation of vBulletin version 4.1.10 is affected by CVE-2012-4686, making it vulnerable to SQL injection attacks.