← All CVEs

CVE-2012-2576

critical · 9.8

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

9.8
CVSS
59.4%
EPSS (exploit prob.)
99th
EPSS percentile
2017-12-20
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
solarwindsbackup_profiler< 5.1.2
solarwindsstorage_manager< 5.1.2
solarwindsstorage_profiler< 5.1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2576