48245Third-party advisory
http://secunia.com/advisories/48245 CVE-2012-4996
Rivettracker 1.03 - Multiple SQL Injections
Record summary
CVE-2012-4996 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRivettracker 1.03 - Multiple SQL InjectionsExploitDB exploitby Ali RaheemNot analyzed1 file
References
718553exploit
http://www.exploit-db.com/exploits/18553 79805vdb entry
http://www.osvdb.org/79805 79806vdb entry
http://www.osvdb.org/79806 52283vdb entry
http://www.securityfocus.com/bid/52283 rivettracker-multiple-sql-injection(73679)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/73679 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-4996