CVE-2012-3820
Campaign Enterprise < 11.0.538 - SQL Injection via SerialNumber or UID Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp.
References (5)
Core 5
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50969
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/86492
Exploit x_refsource_misc
http://sadgeeksinsnow.blogspot.dk/2012/10/my-first-experiences-bug-hunting-part-2.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/79507
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/86491
Scores
EPSS
0.0208
EPSS Percentile
79.5%
Details
CWE
CWE-89
Status
published
Products (1)
arialsoftware/campaign_enterprise
< 11.0.538
Published
Aug 14, 2014
Tracked Since
Feb 18, 2026