CVE-2012-1934

Sourcefabric Newscoop - SQL Injection

Title source: rule

Description

SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/18752

Scores

EPSS 0.0153
EPSS Percentile 81.0%

Classification

CWE
CWE-89
Status draft

Affected Products (6)

sourcefabric/newscoop
sourcefabric/newscoop
sourcefabric/newscoop
sourcefabric/newscoop
sourcefabric/newscoop
sourcefabric/newscoop

Timeline

Published Aug 27, 2012
Tracked Since Feb 18, 2026