CVE-2012-3953

EUVD-2012-3897
SQL injection vulnerability in admin/index.php in phpList before 2.10.19 allows remote administrators to execute arbitrary SQL commands via the delete parameter to the editattributes page.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
phplistphplist
𝑥
≤ 2.10.18
phplistphplist
2.6.5
phplistphplist
2.7.1
phplistphplist
2.7.2
phplistphplist
2.8.2
phplistphplist
2.8.7
phplistphplist
2.8.12
phplistphplist
2.10.1
phplistphplist
2.10.2
phplistphplist
2.10.3
phplistphplist
2.10.4
phplistphplist
2.10.5
phplistphplist
2.10.7
phplistphplist
2.10.8
phplistphplist
2.10.9
phplistphplist
2.10.10
phplistphplist
2.10.11
phplistphplist
2.10.12
phplistphplist
2.10.13
phplistphplist
2.10.14
phplistphplist
2.10.15
phplistphplist
2.10.16
phplistphplist
2.10.17
𝑥
= Vulnerable software versions