CVE-2012-5874

high
Published 2013-01-12 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f) register.php, (g) Search.php, (h) viewboard.php, or (i) viewtopic.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/51622

Application impact

VendorProductVersionsFixed
elite-boardelite_bulletin_board{"endIncluding":"2.1.21"}
elite-boardelite_bulletin_board2.0.0
elite-boardelite_bulletin_board2.0.1
elite-boardelite_bulletin_board2.0.2
elite-boardelite_bulletin_board2.0.3
elite-boardelite_bulletin_board2.1.0
elite-boardelite_bulletin_board2.1.1
elite-boardelite_bulletin_board2.1.2
elite-boardelite_bulletin_board2.1.3
elite-boardelite_bulletin_board2.1.4
elite-boardelite_bulletin_board2.1.5
elite-boardelite_bulletin_board2.1.6
elite-boardelite_bulletin_board2.1.7
elite-boardelite_bulletin_board2.1.8
elite-boardelite_bulletin_board2.1.9
elite-boardelite_bulletin_board2.1.10
elite-boardelite_bulletin_board2.1.11
elite-boardelite_bulletin_board2.1.12
elite-boardelite_bulletin_board2.1.13
elite-boardelite_bulletin_board2.1.14
elite-boardelite_bulletin_board2.1.15
elite-boardelite_bulletin_board2.1.16
elite-boardelite_bulletin_board2.1.17
elite-boardelite_bulletin_board2.1.18
elite-boardelite_bulletin_board2.1.19
elite-boardelite_bulletin_board2.1.20

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.