CVE-2012-3953
phplist < 2.10.19 - Authenticated SQL Injection via Edit Attributes Delete Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-3953. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in PHPList versions prior to 2.10.19. The PoC includes multiple SQLi payloads to extract database version information, read local files, and execute arbitrary JavaScript via SQL queries.
Description
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in PHPList versions prior to 2.10.19. The PoC includes multiple SQLi payloads to extract database version information, read local files, and execute arbitrary JavaScript via SQL queries.