CVE-2012-1002: Zakongroup Openconf

High severity, CVSS 10.0. EPSS: 4.5% chance of exploitation in the next 30 days.

SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

Affected products

  • Zakongroup Openconf: version 4.00 only; version 4.01 only; version 4.02 only; version 4.10 only; version 4.11 only

Published 2012-02-08. Last modified 2026-06-16.