Vulnerability record · CVE-2012-2962 · published 30 July 2012
CVE-2012-2962: Plixer Scrutinizer statusFilter.php SQL injection
Sonicwall · Scrutinizer
Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is passed into SQL without proper sanitization, letting an authenticated remote user run arbitrary SQL against the application's database. Because Scrutinizer is a network monitoring and reporting platform, compromise of its database can expose collected traffic and device data.
Description
SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code and a very high EPSS score make this SQL injection readily exploitable by any authenticated user, though it is not in KEV and requires valid credentials.
What it is
Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is passed into SQL without proper sanitization, letting an authenticated remote user run arbitrary SQL against the application's database. Because Scrutinizer is a network monitoring and reporting platform, compromise of its database can expose collected traffic and device data.
Impact
An attacker with a valid account can execute arbitrary SQL commands, reading or altering database contents and potentially pivoting to other data the application can reach. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through the d4d/statusFilter.php endpoint via the q parameter. Authentication is required (Au:S in the CVSS vector); no user interaction is indicated.
Exploitation
Public exploit code exists (Exploit-DB 20033 and SecurityFocus BID 54625 are tagged Exploit), and EPSS gives a 30-day probability of 0.66828 (99.257th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Upgrade Plixer/Dell SonicWALL Scrutinizer to version 9.5.2 or later, which the vendor states fixes this issue.
- If immediate upgrade is not possible, restrict network access to the Scrutinizer web interface to trusted management networks.
- Review and reduce the number of accounts with access to the affected interface, and enforce least privilege.
- Apply input validation or a WAF rule blocking SQL metacharacters in the q parameter as a temporary compensating control.
Detection
- Inspect web server and application logs for requests to d4d/statusFilter.php with suspicious q parameter values containing SQL syntax.
- Monitor database logs for anomalous queries or errors originating from the Scrutinizer application account.
- Alert on unusual data access or export patterns from Scrutinizer following authenticated sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-2962 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2962), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.