CVE-2012-4927
15.09.2012, 17:55
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
Vendor | Product | Version |
---|---|---|
limesurvey | limesurvey | 𝑥 ≤ 1.90\+ |
limesurvey | limesurvey | 1.5.2 |
limesurvey | limesurvey | 1.49 |
limesurvey | limesurvey | 1.49:rc2 |
limesurvey | limesurvey | 1.49_rc2:_rc2 |
limesurvey | limesurvey | 1.52 |
limesurvey | limesurvey | 1.70 |
limesurvey | limesurvey | 1.80 |
limesurvey | limesurvey | 1.80:rc4 |
limesurvey | limesurvey | 1.80\+ |
limesurvey | limesurvey | 1.81 |
limesurvey | limesurvey | 1.81\+ |
𝑥
= Vulnerable software versions
References