CVE-2012-4927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/09/2012
Last modified:
11/04/2025

Description

SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* 1.90\+ (including)
cpe:2.3:a:limesurvey:limesurvey:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.49:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.49:rc2:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.49_rc2:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.52:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.70:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.80:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.80:rc4:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.80\+:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.81:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:1.81\+:*:*:*:*:*:*:*