PoC Index

CVE-2012-2576

HIGH 10.0EPSS 59.4%

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
59.41% chance of exploitation in the next 30 days, 99th percentile
Published
2017-12-20
Updated
2024-08-06

Proof-of-concept exploits (2)

Metasploit modules (1)

ExploitDB entries (1)

References

Related