CVE-2012-0980

phux Download Manager - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0980. PoCs published by Red Security TEAM.

AI-analyzed exploit summary This is a writeup describing a Blind SQL Injection vulnerability in phux Download Manager. It provides the vulnerable endpoint but lacks executable exploit code or payload details.

Description

SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Red Security TEAM · textwebappsphp
https://www.exploit-db.com/exploits/18432

This is a writeup describing a Blind SQL Injection vulnerability in phux Download Manager. It provides the vulnerable endpoint but lacks executable exploit code or payload details.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: phux Download Manager (version unspecified)
No auth needed
Prerequisites: access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51725
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18432
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72826

Scores

EPSS 0.0109
EPSS Percentile 61.1%

Details

CWE
CWE-89
Status published
Products (1)
phux/download_manager
Published Feb 02, 2012
Tracked Since Feb 18, 2026