10
CVSSv2

CVE-2012-2576

Published: 20/12/2017 Updated: 11/01/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager prior to 5.1.2, SolarWinds Storage Profiler prior to 5.1.2, and SolarWinds Backup Profiler prior to 5.1.2 allows remote malicious users to execute arbitrary SQL commands via the loginName field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds storage profiler

solarwinds backup profiler

solarwinds storage manager

Exploits

#!/usr/bin/python ###################################################################################### # Exploit Title: Solarwinds Storage Manager 510 Remote SYSTEM SQL Injection Exploit # Date: May 2nd 2012 # Author: muts # Version: SolarWinds Storage Manager 510 # Tested on: Windows 2003 # Archive Url : wwwoffensive-securitycom/0da ...