Exploitation Summary
EIP tracks 3 public exploits for CVE-2012-2962.
PoCs published by Metasploit, muts, muts, Devon Kearns, sinn3r, including Metasploit module exploits/windows/http/sonicwall_scrutinizer_sqli.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in Dell SonicWALL Scrutinizer 9.5.1 or older, allowing unauthenticated remote code execution by injecting a PHP payload into the 'q' parameter and writing it to a file in the web root.
Description
SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.
Exploits (3)
This Metasploit module exploits a SQL injection vulnerability in Dell SonicWALL Scrutinizer 9.5.1 or older, allowing unauthenticated remote code execution by injecting a PHP payload into the 'q' parameter and writing it to a file in the web root.
This exploit targets a SQL injection vulnerability in Dell SonicWALL Scrutinizer 9.0.1 via the 'q' parameter in statusFilter.php. It injects a malicious PHP script into the web server's directory, enabling remote code execution.
This Metasploit module exploits a SQL injection vulnerability in Dell SonicWALL Scrutinizer 9.5.1 or older, allowing unauthenticated remote code execution by injecting a PHP payload into the 'q' parameter and writing it to a file via SQLi.