CVE-2012-4743

Siche search module 0.5 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) category parameters.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53035
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/81178
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74916
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-04/0099.html

Scores

EPSS 0.0131
EPSS Percentile 67.7%

Details

CWE
CWE-89
Status published
Products (1)
eos.pe/siche_search_module 0.5
Published Aug 31, 2012
Tracked Since Feb 18, 2026