CVE-2012-2937
Last modified
CVE-2012-2937 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admin_index.php, (2) display parameter in a minimize action to admin/admin_index.php, (3) enabled[] parameter to admin/admin_users.php, or (4) msg_id to the module.php in the simple_messaging module.. EPSS estimates a 2.45% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) list parameter in a move action to admin/admin_index.php, (2) display parameter in a minimize action to admin/admin_index.php, (3) enabled[] parameter to admin/admin_users.php, or (4) msg_id to the module.php in the simple_messaging module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pligg | Pligg Cms | All versions |
| Pligg | Pligg Cms | <= 1.2.1 |
| Pligg | Pligg Cms | 1.0.0 |
| Pligg | Pligg Cms | 1.0.1 |
| Pligg | Pligg Cms | 1.0.2 |
| Pligg | Pligg Cms | 1.0.3 |
| Pligg | Pligg Cms | 1.0.4 |
| Pligg | Pligg Cms | 1.1.0 |
| Pligg | Pligg Cms | 1.1.2 |
| Pligg | Pligg Cms | 1.1.3 |
| Pligg | Pligg Cms | 1.1.4 |
| Pligg | Pligg Cms | 1.1.5 |
| Pligg | Pligg Cms | 1.2.0 |
| Pligg | Pligg Cms | 9.5 |
| Pligg | Pligg Cms | 9.9 |
| Pligg | Pligg Cms | 9.9.0 |
| Pligg | Pligg Cms | 9.9.5 |
References
- http://secunia.com/advisories/45431Vendor Advisory
- http://secunia.com/secunia_research/2012-19/Vendor Advisory
- http://secunia.com/advisories/45431Vendor Advisory
- http://secunia.com/secunia_research/2012-19/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2937?
How severe is CVE-2012-2937?
How do I fix CVE-2012-2937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-2930Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-2931PHP code injection in TinyWebGallery before 1.8.8 allows rem…7.2
- CVE-2012-2932Multiple cross-site scripting (XSS) vulnerabilities in TinyW…
- CVE-2012-2934Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" …
- CVE-2012-2935Cross-site scripting (XSS) vulnerability in osCommerce/OM/Co…
- CVE-2012-2936Multiple cross-site scripting (XSS) vulnerabilities in Pligg…
- CVE-2012-2938Multiple cross-site scripting (XSS) vulnerabilities in Trave…
- CVE-2012-2939Multiple unrestricted file upload vulnerabilities in Travelo…
- CVE-2012-2940MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to c…
- CVE-2012-2941Cross-site scripting (XSS) vulnerability in search/ in Yande…
- CVE-2012-2942Buffer overflow in the trash buffer in the header capture fu…
- CVE-2012-2943CRLF injection vulnerability in cryptographp.inc.php in Cryp…
Are you affected by CVE-2012-2937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
