CVE-2012-4927: SQL Injection
Published Sep 15, 2012
·Updated
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
Affected Software
13 affected components
Limesurvey LimeSurvey
Limesurvey LimeSurvey<=1.90\+
Limesurvey LimeSurvey=1.5.2
Limesurvey LimeSurvey=1.49
Limesurvey LimeSurvey=1.49-rc2
Limesurvey LimeSurvey=1.49_rc2
Limesurvey LimeSurvey=1.52
Limesurvey LimeSurvey=1.70
Limesurvey LimeSurvey=1.80
Limesurvey LimeSurvey=1.80-rc4
Limesurvey LimeSurvey=1.80\+
Limesurvey LimeSurvey=1.81
Limesurvey LimeSurvey=1.81\+
Event History
Sep 15, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4927?
CVE-2012-4927 is considered a high-severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2012-4927?
To mitigate CVE-2012-4927, you should upgrade LimeSurvey to version 1.91+ Build 120224 or later.
3
What are the affected versions in CVE-2012-4927?
CVE-2012-4927 affects all versions of LimeSurvey prior to 1.91+ Build 120224.
4
What types of attacks can occur due to CVE-2012-4927?
CVE-2012-4927 allows attackers to execute arbitrary SQL commands, leading to data breaches or database manipulation.
5
Is CVE-2012-4927 specific to any feature in LimeSurvey?
Yes, CVE-2012-4927 specifically exploits the 'fieldnames' parameter in index.php.