CVE-2012-6520

Wikidforum 2.10 - SQL Injection via Advanced Search Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-6520. PoCs published by Stefan Schurtz.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Wikidforum 2.10, specifically in the 'select_sort' and 'opt_search_select' POST parameters during advanced searches. It lacks executable exploit code but details the attack vectors.

Description

Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Stefan Schurtz · textwebappsphp
https://www.exploit-db.com/exploits/36946

The provided text describes SQL injection and XSS vulnerabilities in Wikidforum 2.10, specifically in the 'select_sort' and 'opt_search_select' POST parameters during advanced searches. It lacks executable exploit code but details the attack vectors.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Wikidforum 2.10
No auth needed
Prerequisites: Access to the advanced search functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73980
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/13/4
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-03/0046.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/12/12
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52425
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/15/1

Scores

EPSS 0.0127
EPSS Percentile 66.0%

Details

CWE
CWE-89
Status published
Products (1)
wikidforum/wikidforum 2.10
Published Jan 24, 2013
Tracked Since Feb 18, 2026