0nto.wordpress.com
http://0nto.wordpress.com/2012/02/13/sths-v2-web-portal-2-2-sql-injection-vulnerabilty CVE-2012-1217
STHS v2 Web Portal - 'prospects.php?team' SQL Injection
Record summary
CVE-2012-1217 has a selected CVSS score of 4.3; EIP currently links 3 catalogued exploits.
Description
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBSTHS v2 Web Portal - 'prospects.php?team' SQL InjectionExploitDB exploitby Liyan OzNot analyzed1 file
ExploitDBSTHS v2 Web Portal - 'prospect.php?team' SQL InjectionExploitDB exploitby Liyan OzNot analyzed1 file
ExploitDBSTHS v2 Web Portal - 'team.php?team' SQL InjectionExploitDB exploitby Liyan OzNot analyzed1 file
References
5packetstormsecurity.org
http://packetstormsecurity.org/files/109665/STHS-v2-Web-Portal-2.2-SQL-Injection.html 51991vdb entry
http://www.securityfocus.com/bid/51991 sths-prospects-team-sql-injection(73154)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/73154 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1217