CVE-2012-5244 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 74)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.5% — more likely to be exploited than 74% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-10-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| bananadance | banana dance |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | banana dance b.2.6 - Multiple Vulnerabilities | 2012-12-21 |
References
- http://osvdb.org/88535
- http://osvdb.org/88536
- http://osvdb.org/88537
- http://osvdb.org/88538
- http://www.exploit-db.com/exploits/23573/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80746
- https://www.htbridge.com/advisory/HTB23118
- http://osvdb.org/88535
- http://osvdb.org/88536
- http://osvdb.org/88537
- http://osvdb.org/88538
- http://www.exploit-db.com/exploits/23573/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80746
- https://www.htbridge.com/advisory/HTB23118
→ the Explorer · watch your stack · NVD