admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2012-03/0115.html - | |
References | () http://downloads.sourceforge.net/project/php-gradebook/phpGradeBook%20-%20BETA/1.9.5/phpGradeBook1.9.5.zip - Patch | |
References | () http://osvdb.org/80311 - | |
References | () http://secunia.com/advisories/48524 - | |
References | () http://www.exploit-db.com/exploits/18647/ - Exploit | |
References | () http://www.securityfocus.com/bid/52686 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74292 - |
Information
Published : 2012-03-31 14:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-1670
Mitre link : CVE-2012-1670
CVE.ORG link : CVE-2012-1670
JSON object : View
Products Affected
phpgradebook
- php_grade_book
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor