peter bassill · operator
$ cve CVE-2012-5244 JSON

CVE-2012-5244 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 74)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.5% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-10-20
Last modified2026-06-16

Affected (1)

VendorProduct
bananadancebanana dance

Public exploits

SourceTitleDate
exploit-dbbanana dance b.2.6 - Multiple Vulnerabilities2012-12-21

References

→ the Explorer  ·  watch your stack  ·  NVD