CVE-2012-1002

EUVD-2012-1042
SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
zakongroupopenconf
4.00
zakongroupopenconf
4.01
zakongroupopenconf
4.02
zakongroupopenconf
4.10
zakongroupopenconf
4.11
𝑥
= Vulnerable software versions