CVE-2012-5701

dotproject < 2.1.7 - Authenticated SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5701. PoCs published by High-Tech Bridge.

AI-analyzed exploit summary The exploit demonstrates multiple SQL injection vulnerabilities in Dotproject versions prior to 2.1.7. It includes URLs with crafted SQL queries that leverage UNION-based injection to write data to files, potentially leading to data exfiltration or further exploitation.

Description

Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5) company_id parameter in a system action to index.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/38042

The exploit demonstrates multiple SQL injection vulnerabilities in Dotproject versions prior to 2.1.7. It includes URLs with crafted SQL queries that leverage UNION-based injection to write data to files, potentially leading to data exfiltration or further exploitation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dotproject < 2.1.7
No auth needed
Prerequisites: Access to the target application's web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/87625
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/80223
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56624

Scores

EPSS 0.0068
EPSS Percentile 47.5%

Details

CWE
CWE-352 CWE-89
Status published
Products (1)
dotproject/dotproject < 2.1.6
Published Oct 20, 2014
Tracked Since Feb 18, 2026