VULNERABILITY INTELLIGENCE
CVE-2012-2576
CVSS score9.8 CRITICAL
EPSS probability59.41%
CISA KEVNot currently listed
Published2017-12-20
Last modified2026-06-16
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
Weakness classification
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Primary references
- cret@cert.org — Exploit, Third Party Advisory, VDB Entry
- cret@cert.org — Exploit, Third Party Advisory, VDB Entry
- cret@cert.org — Third Party Advisory, VDB Entry
- cret@cert.org — Vendor Advisory
- cret@cert.org — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Exploit, Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry