CVE-2012-3998

high
Published 2012-07-12 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple SQL injection vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to execute arbitrary SQL commands via the (1) paste id in admin/modules/mod_pastes.php or (2) show.php, (3) user id to admin/modules/mod_users.php, (4) project to list.php, or (5) session id to show.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://gitorious.org/sticky-notes/sticky-notes/commit/d97475f07520d61af3d20fbaeb2e9a974c190308

Application impact

VendorProductVersionsFixed
sayakbanerjeesticky_notes{"endIncluding":"0.2.27052012.5"}
sayakbanerjeesticky_notes0.2.27052012.4

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.