CVE-2012-3820
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- arialsoftware/campaign enterprise
- Source
- cve@mitre.org
References
- http://osvdb.org/86491
- http://osvdb.org/86492
- http://sadgeeksinsnow.blogspot.dk/2012/10/my-first-experiences-bug-hunting-part-2.htmlExploit
- http://secunia.com/advisories/50969
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79507
- http://osvdb.org/86491
- http://osvdb.org/86492
- http://sadgeeksinsnow.blogspot.dk/2012/10/my-first-experiences-bug-hunting-part-2.htmlExploit
- http://secunia.com/advisories/50969
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79507
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.