SQL Injection Vulnerability in Proman Xpress by Proman Systems
CVE-2012-4265

Currently unrated

Key Information:

Vendor
CVE Published:
13 August 2012

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2012-4265?

An SQL injection vulnerability exists in the category_edit.php file of Proman Xpress 5.0.1. This flaw allows remote attackers to manipulate SQL queries executed by the application through the 'cid' parameter, potentially enabling them to execute arbitrary SQL commands, which can compromise data integrity and security.

References

Timeline

  • Vulnerability Reserved

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

.