CVE-2012-2576 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 59.4% (pctl 99)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 59.41% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-12-20 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| solarwinds | backup profiler |
| solarwinds | storage manager |
| solarwinds | storage profiler |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SolarWinds Storage Manager 5.1.0 - Remote SYSTEM SQL Injection | 2012-05-01 |
References
- http://www.exploit-db.com/exploits/18818
- http://www.exploit-db.com/exploits/18833
- http://www.securityfocus.com/bid/51639
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680
- http://www.exploit-db.com/exploits/18818
- http://www.exploit-db.com/exploits/18833
- http://www.securityfocus.com/bid/51639
- http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72680
→ the Explorer · watch your stack · NVD