CVE-2012-3873

Openconstructor - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6) data/event/edit.php.

Exploits (1)

exploitdb WRITEUP
by Lorenzo Cantoni · textwebappsphp
https://www.exploit-db.com/exploits/20347

References (1)

Core 1

Scores

EPSS 0.0094
EPSS Percentile 76.3%

Details

CWE
CWE-89
Status published
Products (1)
openconstructor_project/openconstructor 3.12.0
Published Dec 28, 2012
Tracked Since Feb 18, 2026