CVE-2012-5328
Summary
| CVE | CVE-2012-5328 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-08 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4) edit_forum_id parameter in an edit_save_forum action to fs-admin/wpf-edit-forum-group.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cartpauj | Mingle-forum | 1.0.00 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.01 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.02 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.03 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.04 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.05 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.06 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.07 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.08 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.09 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.10 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.11 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.12 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.13 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.14 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.15 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.16 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.17 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.18 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.19 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.20 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.21 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.21.1 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.22 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.23 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.23.1 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.23.2 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.24 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.25 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.26 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.27 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.28 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.28.1 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.28.2 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.29 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.30 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.31 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.31.1 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.31.2 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.31.3 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.31.4 | All | All | All |
| Application | Cartpauj | Mingle-forum | 1.0.32 | All | All | All |
| Application | Cartpauj | Mingle-forum | All | All | All | All |
| Application | Wordpress | Wordpress | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | |
| WordPress › Mingle Forum « WordPress Plugins | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | |
| 403 Forbidden | MITRE | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.