47468Third-party advisory
http://secunia.com/advisories/47468 CVE-2012-5348
MangosWeb - SQL Injection
Record summary
CVE-2012-5348 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMangosWeb - SQL InjectionExploitDB exploitby Hood3dRob1nNot analyzed1 file
References
518335exploit
http://www.exploit-db.com/exploits/18335 51314vdb entry
http://www.securityfocus.com/bid/51314 mangosweb-index-sql-injection(72231)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/72231 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-5348