CVE-2012-4772: SQL Injection
Published Oct 22, 2012
·Updated
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
Affected Software
4 affected components
Intelliants Subrion CMS<=2.2.2
Intelliants Subrion CMS=2.0.4
Intelliants Subrion CMS=2.2.0
Intelliants Subrion CMS=2.2.1
Event History
Oct 22, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4772?
CVE-2012-4772 has a high severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2012-4772?
To fix CVE-2012-4772, it is recommended to upgrade to Subrion CMS version 2.2.3 or later.
3
What are the affected versions by CVE-2012-4772?
The affected versions of Subrion CMS are all versions prior to 2.2.3, including 2.0.4, 2.2.0, 2.2.1.
4
Can CVE-2012-4772 be exploited remotely?
Yes, CVE-2012-4772 can be exploited remotely by attackers through the plan_id parameter in the register endpoint.
5
What type of vulnerability is CVE-2012-4772?
CVE-2012-4772 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.