CVE-2012-6507
ChurchCMS 0.0.1 - SQL Injection via uname or pass Parameter
Title source: llmDescription
Multiple SQL injection vulnerabilities in admin.php in ChurchCMS 0.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameters in a login action.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75110
Exploit mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-04/0178.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/53209
Exploit x_refsource_misc
http://packetstormsecurity.org/files/112106/ChurchCMS-0.0.1-SQL-Injection.html
Scores
EPSS
0.0130
EPSS Percentile
67.5%
Details
CWE
CWE-89
Status
published
Products (1)
jason_sexauer/churchcms
0.0.1
Published
Jan 24, 2013
Tracked Since
Feb 18, 2026