CVE-2012-1002

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/02/2012
Last modified:
11/04/2025

Description

SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zakongroup:openconf:4.00:*:*:*:*:*:*:*
cpe:2.3:a:zakongroup:openconf:4.01:*:*:*:*:*:*:*
cpe:2.3:a:zakongroup:openconf:4.02:*:*:*:*:*:*:*
cpe:2.3:a:zakongroup:openconf:4.10:*:*:*:*:*:*:*
cpe:2.3:a:zakongroup:openconf:4.11:*:*:*:*:*:*:*