Unrated severityNVD Advisory· Published Sep 15, 2012· Updated Apr 29, 2026
CVE-2012-4927
CVE-2012-4927
Description
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
Affected products
12cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.49:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.49:rc2:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.49_rc2:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.52:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.70:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.80:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.80\+:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.80:rc4:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.81:*:*:*:*:*:*:*
- cpe:2.3:a:limesurvey:limesurvey:1.81\+:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- packetstormsecurity.org/files/110100/limesurvey-sql.txtnvdExploit
- www.exploit-db.com/exploits/18508nvdExploit
- secunia.com/advisories/48051nvdVendor Advisory
- freecode.com/projects/limesurvey/releases/342070nvd
- osvdb.org/79459nvd
- www.limesurvey.org/en/stable-releasenvd
- www.securityfocus.com/bid/52114nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/73395nvd
News mentions
0No linked articles in our index yet.