Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-5910

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2012-5910
Last Modified 19 Nov 2012 12:00:00
Published 17 Nov 2012 04:55:05
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2012-5910

Summary

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

Vulnerable Systems

Application

  • B2evolution 4.1.3


References

XF - b2evolutioncms-viewfile-sql-injection(74457)

BID - 52783

MISC - http://vulnerability-lab.com/get_content.php?id=482

MISC - http://packetstormsecurity.org/files/111294/B2Evolution-CMS-4.1.3-SQL-Injection.html

OSVDB - 80671

MISC - http://b2evolution.net/news/2012/04/06/b2evolution-4-1-4-stable


Last Updated: 27 May 2016 10:53:45