CVE-2012-3477

NeoInvoice - SQL Injection via Signup Check Username Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action.

References (2)

Core 2
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-08/0087.html

Scores

EPSS 0.0120
EPSS Percentile 65.0%

Details

CWE
CWE-89
Status published
Products (1)
thomas_hunter/neoinvoice
Published Aug 26, 2012
Tracked Since Feb 18, 2026