6.5
CVSSv2

CVE-2012-6290

Published: 11/03/2014 Updated: 29/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in ImageCMS prior to 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated malicious users to execute arbitrary SQL commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagecms imagecms

Exploits

Advisory ID: HTB23132 Product: ImageCMS Vendor: wwwimagecmsnet Vulnerable Version(s): 400b and probably prior Tested Version: 400b Vendor Notification: December 5, 2012 Vendor Patch: January 16, 2013 Public Disclosure: January 23, 2013 Vulnerability Type: SQL Injection [CWE-89] CVE Reference: CVE-2012-6290 Risk Level: Medium CVSSv2 Base S ...
ImageCMS version 400b suffers from a remote SQL injection vulnerability ...