CVE-2012-1002: Zakongroup Openconf
High severity, CVSS 10.0. EPSS: 4.5% chance of exploitation in the next 30 days.
SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Affected products
- Zakongroup Openconf: version 4.00 only; version 4.01 only; version 4.02 only; version 4.10 only; version 4.11 only
Published 2012-02-08. Last modified 2026-06-16.