CVE-2012-2740

SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbitrary SQL commands via the sortby parameter in a find action.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phplist:phplist:*:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.3:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.4:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.5:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.7:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.8:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.9:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.10:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.11:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.12:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.13:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.14:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.15:*:*:*:*:*:*:*
cpe:2.3:a:phplist:phplist:2.10.16:*:*:*:*:*:*:*

History

21 Nov 2024, 01:39

Type Values Removed Values Added
References () http://securitytracker.com/id?1027181 - () http://securitytracker.com/id?1027181 -
References () http://www.exploit-db.com/exploits/18639 - Exploit () http://www.exploit-db.com/exploits/18639 - Exploit
References () http://www.openwall.com/lists/oss-security/2012/06/16/1 - () http://www.openwall.com/lists/oss-security/2012/06/16/1 -
References () http://www.openwall.com/lists/oss-security/2012/06/17/2 - () http://www.openwall.com/lists/oss-security/2012/06/17/2 -
References () http://www.securityfocus.com/bid/52657 - Exploit () http://www.securityfocus.com/bid/52657 - Exploit
References () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5081.php - () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5081.php -
References () https://mantis.phplist.com/view.php?id=16557 - () https://mantis.phplist.com/view.php?id=16557 -
References () https://www.phplist.com/?lid=567 - Vendor Advisory, Patch () https://www.phplist.com/?lid=567 - Patch, Vendor Advisory

Information

Published : 2012-09-06 17:55

Updated : 2024-11-21 01:39


NVD link : CVE-2012-2740

Mitre link : CVE-2012-2740

CVE.ORG link : CVE-2012-2740


JSON object : View

Products Affected

phplist

  • phplist
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')