Back to Database
Status published
Medium
CVE-2012-5910
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote...
Vulnerability Description
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5910
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/80671
- http://packetstormsecurity.org/files/111294/B2Evolution-CMS-4.1.3-SQL-Injection.html
- http://www.securityfocus.com/bid/52783
- http://vulnerability-lab.com/get_content.php?id=482
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74457
- http://b2evolution.net/news/2012/04/06/b2evolution-4-1-4-stable
More from b2evolution
View All →CVE-2022-44036
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload...
Unknown
0
CVE-2022-30935
An authorization bypass in b2evolution allows remote, unauthenticated attackers to...
Unknown
0
CVE-2021-31632
b2evolution CMS v7.2.3 was discovered to contain a SQL injection...
Critical
9.8
CVE-2021-31631
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request...
High
8.8
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows...
High
8.8
Affected Vendor
b2evolution
View all reports →Affected Software
b2evolution
Vulnerable Versions:
4.1.3
Timeline
Official Publish:
November 17th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.