CVE-2012-4990: SQL Injection
SQL injection vulnerability in admin/campaign-zone-link.php in OpenX 2.8.10 before revision 81823 allows remote attackers to execute arbitrary SQL commands via the ids[] parameter in a link action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4990?
CVE-2012-4990 is rated as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2012-4990?
To fix CVE-2012-4990, upgrade to the latest version of OpenX beyond 2.8.10 or apply available patches that address the SQL injection flaw.
What software is affected by CVE-2012-4990?
CVE-2012-4990 affects OpenX version 2.8.10 prior to revision 81823.
What type of vulnerability is CVE-2012-4990?
CVE-2012-4990 is an SQL injection vulnerability that allows the execution of arbitrary SQL commands.
Can CVE-2012-4990 lead to data breaches?
Yes, CVE-2012-4990 can lead to data breaches by allowing attackers to manipulate or extract sensitive data from the database.