CVE-2012-5289

Plogger 1.0 RC1 - SQL Injection via id Parameter

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php.

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51228
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72079
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027608

Scores

EPSS 0.0131
EPSS Percentile 67.7%

Details

CWE
CWE-89
Status published
Products (1)
plogger/plogger 1.0 rc1
Published Oct 04, 2012
Tracked Since Feb 18, 2026