CVE-2012-2576

CRITICAL

SolarWinds <5.1.2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18833
exploitdb WORKING POC VERIFIED
by muts · pythonremotewindows
https://www.exploit-db.com/exploits/18818

Scores

CVSS v3 9.8
EPSS 0.4108
EPSS Percentile 97.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (3)
solarwinds/backup_profiler < 5.1.2
solarwinds/storage_manager < 5.1.2
solarwinds/storage_profiler < 5.1.2
Published Dec 20, 2017
Tracked Since Feb 18, 2026