CVE-2012-5874
Published Jan 12, 2013
Last updated 12 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f) register.php, (g) Search.php, (h) viewboard.php, or (i) viewtopic.php.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "642DA637-C031-4425-AD6A-906FCDFFBA28", "versionEndIncluding": "2.1.21" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E713D1D0-2079-435E-9091-A6033050A1CE" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "236DD297-3957-431E-A001-7D0BBC87355B" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED8C6423-B898-4142-9B0D-974AF85A0454" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C621BF7C-96EF-4AB6-9157-E56A2A41FD78" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C2880E0-96AB-475B-8469-5FFF7B15B508" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A41ADD9C-6643-47B2-96B2-E5688C172D5D" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E80CAC3-3173-4C99-97A6-E58B9B076042" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B631C1D7-8CEA-4A0E-8D1E-D4BA0161F66D" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F865810-8535-4F20-8CE9-AA47BBE37DBE" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4BED5CC-919B-4B84-AE0D-DF18B5F48E7A" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F78C40F9-0C21-4D47-A459-971CD31F4156" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "032110B9-2EF5-4793-B7C6-561C59823F4B" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13B171DA-3648-471D-8998-44B253717443" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EE36B7A-FDAD-4177-962E-370E09455A7C" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24AFB122-8870-4418-B599-99388B309532" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AB1F558-F10F-472A-86B6-141988C72168" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D1300CD-E63D-4E84-8CB2-D425BE533544" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1062568C-620B-45B3-AB44-9BCE6897AA5B" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B4B791C-2ADF-43B2-A17F-9E8207EEEFF5" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F1E9D6A-B9A8-42A7-B545-CBE49ECF0DF2" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3BFC0A1-C74D-4764-886D-E01D3FC9CE4C" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B79A8EDF-5299-4323-9BCF-DF3C17DBDA71" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0411B85A-B04D-4980-8DC7-D37257DE4678" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B927D9F-2EB1-4DD3-837A-5E55760732F7" }, { "criteria": "cpe:2.3:a:elite-board:elite_bulletin_board:2.1.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05AAA0F5-EB37-4296-A953-E330BDD18B04" } ], "operator": "OR" } ] } ]