← Vulnerability feed

Vulnerability record · CVE-2012-2962 · published 30 July 2012

CVE-2012-2962: Plixer Scrutinizer statusFilter.php SQL injection

Sonicwall · Scrutinizer

Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is passed into SQL without proper sanitization, letting an authenticated remote user run arbitrary SQL against the application's database. Because Scrutinizer is a network monitoring and reporting platform, compromise of its database can expose collected traffic and device data.

6.5 CVSS 2.0 Medium EPSS 67% · top 0.7% CWE-89 · SQL injection
6.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityPublic exploit code and a very high EPSS score make this SQL injection readily exploitable by any authenticated user, though it is not in KEV and requires valid credentials.

What it is

Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is passed into SQL without proper sanitization, letting an authenticated remote user run arbitrary SQL against the application's database. Because Scrutinizer is a network monitoring and reporting platform, compromise of its database can expose collected traffic and device data.

Impact

An attacker with a valid account can execute arbitrary SQL commands, reading or altering database contents and potentially pivoting to other data the application can reach. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reachable over the network through the d4d/statusFilter.php endpoint via the q parameter. Authentication is required (Au:S in the CVSS vector); no user interaction is indicated.

Exploitation

Public exploit code exists (Exploit-DB 20033 and SecurityFocus BID 54625 are tagged Exploit), and EPSS gives a 30-day probability of 0.66828 (99.257th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade Plixer/Dell SonicWALL Scrutinizer to version 9.5.2 or later, which the vendor states fixes this issue.
  • If immediate upgrade is not possible, restrict network access to the Scrutinizer web interface to trusted management networks.
  • Review and reduce the number of accounts with access to the affected interface, and enforce least privilege.
  • Apply input validation or a WAF rule blocking SQL metacharacters in the q parameter as a temporary compensating control.

Detection

  • Inspect web server and application logs for requests to d4d/statusFilter.php with suspicious q parameter values containing SQL syntax.
  • Monitor database logs for anomalous queries or errors originating from the Scrutinizer application account.
  • Alert on unusual data access or export patterns from Scrutinizer following authenticated sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2012-2627Sonicwall scrutinizer vulnerabilityd4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…EPSS 5.7%7.5CVE-2012-3951Plixer Scrutinizer default admin password enables SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and…EPSS 52%analysed6.5CVE-2014-4977Dell SonicWall Scrutinizer SQL injection in admin and exporter endpointsDell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such…EPSS 75%analysed5.5CVE-2014-4976Sonicwall scrutinizer permissions and access controls vulnerabilityDell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…EPSS 2.7%5.0CVE-2012-2626Sonicwall scrutinizer improper authentication vulnerabilitycgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…EPSS 44%4.3CVE-2012-3848Sonicwall scrutinizer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remo…EPSS 2.5%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2012-2962), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.