Vulnerability Description
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Plixer | Scrutinizer Netflow \& Sflow Analyzer | >= 8.6.2.16204, < 9.0.1.19899 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.org/files/111791/Scrutinizer-8.6.2-Bypass-Cross-Site-ExploitThird Party Advisory
- http://www.exploit-db.com/exploits/18750ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/52989Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74826Third Party AdvisoryVDB Entry
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/twsl2012-008-mulThird Party Advisory
- http://packetstormsecurity.org/files/111791/Scrutinizer-8.6.2-Bypass-Cross-Site-ExploitThird Party Advisory
- http://www.exploit-db.com/exploits/18750ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/52989Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74826Third Party AdvisoryVDB Entry
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/twsl2012-008-mulThird Party Advisory
FAQ
What is CVE-2012-1259?
CVE-2012-1259 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbit...
How severe is CVE-2012-1259?
CVE-2012-1259 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2012-1259?
Check the references section above for vendor advisories and patch information. Affected products include: Plixer Scrutinizer Netflow \& Sflow Analyzer.