CVE-2012-5910

b2evolution 4.1.3 - Authenticated SQL Injection via Root Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80671
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52783
Various Sources x_refsource_misc
http://vulnerability-lab.com/get_content.php?id=482
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74457

Scores

EPSS 0.0115
EPSS Percentile 63.6%

Details

CWE
CWE-89
Status published
Products (1)
b2evolution/b2evolution 4.1.3
Published Nov 17, 2012
Tracked Since Feb 18, 2026