CVE-2012-2576

CRITICAL

SolarWinds <5.1.2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

Exploits (2)

exploitdb WORKING POC VERIFIED
by muts · pythonremotewindows
https://www.exploit-db.com/exploits/18818
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18833

Scores

CVSS v3 9.8
EPSS 0.4108
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-89
Status draft

Affected Products (3)

solarwinds/backup_profiler < 5.1.2
solarwinds/storage_manager < 5.1.2
solarwinds/storage_profiler < 5.1.2

Timeline

Published Dec 20, 2017
Tracked Since Feb 18, 2026