CVE-2012-4927
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDSep 15
1st PoCFeb 22
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/18508unverifiedcve_referencepacketstormsecurity.org/files/110100/limesurvey-sql.txtunverifiedcve_referencewww.exploit-db.com/exploits/18508unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://freecode.com/projects/limesurvey/releases/342070http://osvdb.org/79459http://packetstormsecurity.org/files/110100/limesurvey-sql.txthttp://secunia.com/advisories/48051https://exchange.xforce.ibmcloud.com/vulnerabilities/73395http://www.exploit-db.com/exploits/18508http://www.limesurvey.org/en/stable-releasehttp://www.securityfocus.com/bid/52114