CVE-2012-3953

SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
phplistphplist
𝑥
≤ 2.10.18
phplistphplist
2.6.5
phplistphplist
2.7.1
phplistphplist
2.7.2
phplistphplist
2.8.2
phplistphplist
2.8.7
phplistphplist
2.8.12
phplistphplist
2.10.1
phplistphplist
2.10.2
phplistphplist
2.10.3
phplistphplist
2.10.4
phplistphplist
2.10.5
phplistphplist
2.10.7
phplistphplist
2.10.8
phplistphplist
2.10.9
phplistphplist
2.10.10
phplistphplist
2.10.11
phplistphplist
2.10.12
phplistphplist
2.10.13
phplistphplist
2.10.14
phplistphplist
2.10.15
phplistphplist
2.10.16
phplistphplist
2.10.17
𝑥
= Vulnerable software versions