peter bassill · operator
$ cve CVE-2012-0973 JSON

CVE-2012-0973 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.41% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-09-25
Last modified2026-06-16

Affected (1)

VendorProduct
osclassosclass

Public exploits

SourceTitleDate
exploit-dbOSClass 2.3.3 - 'index.php?sCategory' SQL Injection2012-01-25

References

→ the Explorer  ·  watch your stack  ·  NVD