7.5
CVSSv2

CVE-2012-5244

Published: 20/10/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

bananadance banana dance

Exploits

Advisory ID: HTB23118 Product: Banana Dance Vendor: bananadanceorg Vulnerable Version(s): B26 and probably prior Tested Version: B26 Vendor Notification: October 3, 2012 Public Disclosure: December 19, 2012 Vulnerability Type: PHP File Inclusion [CWE-98], Improper Access Control [CWE-284], SQL Injection [CWE-89] CVE References: CVE-2012-5242 ...
Banana Dance version B26 suffers from local file inclusion, remote SQL injection, and improper access control vulnerabilities ...