CyberRota
Live Feed
Return to register
Case File

CVE-2012-5874

HIGH · CVSS 7.5 EPSS 2.51% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-01-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2012-5874
Severity
HIGH
CVSS
7.5
EPSS
2.51%

Original Filing — NVD Description

Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f) register.php, (g) Search.php, (h) viewboard.php, or (i) viewtopic.php.