CVE-2012-2576
critical · 9.8SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
9.8
CVSS
59.4%
EPSS (exploit prob.)
99th
EPSS percentile
2017-12-20
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| solarwinds | backup_profiler | < 5.1.2 |
| solarwinds | storage_manager | < 5.1.2 |
| solarwinds | storage_profiler | < 5.1.2 |
Check a specific version with /api/v1/cve/match.
References
- http://www.exploit-db.com/exploits/18818
- http://www.exploit-db.com/exploits/18833
- http://www.securityfocus.com/bid/51639
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680
- http://www.exploit-db.com/exploits/18818
- http://www.exploit-db.com/exploits/18833
- http://www.securityfocus.com/bid/51639
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-2576