CVE-2012-5910
b2evolution 4.1.3 - Authenticated SQL Injection via Root Parameter
Title source: llmDescription
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/80671
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.org/files/111294/B2Evolution-CMS-4.1.3-SQL-Injection.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/52783
Various Sources x_refsource_misc
http://vulnerability-lab.com/get_content.php?id=482
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74457
Various Sources x_refsource_misc
http://b2evolution.net/news/2012/04/06/b2evolution-4-1-4-stable
Scores
EPSS
0.0115
EPSS Percentile
63.6%
Details
CWE
CWE-89
Status
published
Products (1)
b2evolution/b2evolution
4.1.3
Published
Nov 17, 2012
Tracked Since
Feb 18, 2026