CVE-2012-2923

Hypermethod eLearning Server 4G - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter.

Exploits (1)

exploitdb WORKING POC
by Andrey Komarov · textwebappsphp
https://www.exploit-db.com/exploits/18858

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18858
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75513
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/81830
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49126
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53472

Scores

EPSS 0.0094
EPSS Percentile 76.4%

Details

CWE
CWE-89
Status published
Products (1)
hypermethod/elearning_server 4g
Published May 21, 2012
Tracked Since Feb 18, 2026