CVE-2012-4282

Toocharger Trombinoscope - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ramdan Yantu · textwebappsphp
https://www.exploit-db.com/exploits/37136

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75427
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53398

Scores

EPSS 0.0055
EPSS Percentile 68.1%

Details

CWE
CWE-89
Status published
Products (1)
toocharger/trombinoscope 3.5
Published Aug 13, 2012
Tracked Since Feb 18, 2026