10
CVSSv2

CVE-2012-1002

Published: 08/02/2012 Updated: 07/12/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in author/edit.php in OpenConf 4.x prior to 4.12 allows remote malicious users to execute arbitrary SQL commands via the pid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

zakongroup openconf 4.11

zakongroup openconf 4.02

zakongroup openconf 4.10

zakongroup openconf 4.00

zakongroup openconf 4.01

Exploits

<?php /* --------------------------------------------------------------------- OpenConf <= 411 (author/editphp) Remote Blind SQL Injection Exploit --------------------------------------------------------------------- author: Egidio Romano aka EgiX mail: n0b0d13s[at]gmail[dot]com software link ...
OpenConf versions 411 and below suffer from a remote blind SQL injection vulnerability ...