peter bassill · operator
$ cve CVE-2012-5912 JSON

CVE-2012-5912 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.42% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-11-17
Last modified2026-06-16

Affected (1)

VendorProduct
picopicopublisher

Public exploits

SourceTitleDate
exploit-dbPicoPublisher 2.0 - SQL Injection2012-03-28

References

→ the Explorer  ·  watch your stack  ·  NVD