CVE-2012-4060

Asp-dev XM Forums - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Farbod Mahini · textwebappsasp
https://www.exploit-db.com/exploits/37119

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53292
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75261

Scores

EPSS 0.0094
EPSS Percentile 76.4%

Details

CWE
CWE-89
Status published
Products (1)
asp-dev/xm_forums
Published Jul 25, 2012
Tracked Since Feb 18, 2026