{"api_version":"1","generated_at":"2026-07-23T19:44:39+00:00","cve":"CVE-2012-0973","urls":{"html":"https://cve.report/CVE-2012-0973","api":"https://cve.report/api/cve/CVE-2012-0973.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-0973","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-0973"},"summary":{"title":"CVE-2012-0973","description":"Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-09-25 23:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/47697","name":"http://secunia.com/advisories/47697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://osclass.org/2012/01/16/osclass-2-3-5/","name":"http://osclass.org/2012/01/16/osclass-2-3-5/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OSClass 2.3.5 | Blog | Osclass the free scripts classifiedBlog | Osclass the free scripts classified | Professional open source classifieds","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html","name":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"High-Tech Bridge SA - Advisories - Multiple vulnerabilities in OSclass","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/51662","name":"http://www.securityfocus.com/bid/51662","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OSClass SQL Injection and Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html","name":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73","name":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OSClass 2.3.5 · osclass/Osclass@ff7ef8a · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-0973","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-0973","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"973","vulnerable":"1","versionEndIncluding":"2.3.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"osclass","cpe5":"osclass","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:45:26.075Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://osclass.org/2012/01/16/osclass-2-3-5/"},{"name":"51662","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/51662"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html"},{"name":"47697","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47697"},{"name":"20120125 Multiple vulnerabilities in OSclass","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-09-25T23:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73"},{"tags":["x_refsource_CONFIRM"],"url":"http://osclass.org/2012/01/16/osclass-2-3-5/"},{"name":"51662","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/51662"},{"tags":["x_refsource_MISC"],"url":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html"},{"name":"47697","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47697"},{"name":"20120125 Multiple vulnerabilities in OSclass","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-0973","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73","refsource":"CONFIRM","url":"https://github.com/osclass/OSClass/commit/ff7ef8a97301aaaf6a97fe46c2c27981a86b4e2f#diff-73"},{"name":"http://osclass.org/2012/01/16/osclass-2-3-5/","refsource":"CONFIRM","url":"http://osclass.org/2012/01/16/osclass-2-3-5/"},{"name":"51662","refsource":"BID","url":"http://www.securityfocus.com/bid/51662"},{"name":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html","refsource":"MISC","url":"https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_osclass.html"},{"name":"47697","refsource":"SECUNIA","url":"http://secunia.com/advisories/47697"},{"name":"20120125 Multiple vulnerabilities in OSclass","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2012-01/0157.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-0973","datePublished":"2012-09-25T23:00:00.000Z","dateReserved":"2012-02-01T00:00:00.000Z","dateUpdated":"2024-09-16T22:25:17.569Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-09-25 23:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:osclass:osclass:*:*:*:*:*:*:*:*","versionEndIncluding":"2.3.4","matchCriteriaId":"CB2C2ED9-6F31-43C2-B007-9E1B2E622539"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"973","Ordinal":"1","Title":"CVE-2012-0973","CVE":"CVE-2012-0973","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"973","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2012-0973"},{"CveYear":"2012","CveId":"973","Ordinal":"2","NoteData":"2012-09-25","Type":"Other","Title":"Published"}]}}}