This post was originally published on this site.
[R2] Nessus Version 10.12.1 Fixes SQL Injection Vulnerabilities
Vulnerabilities have been identified in Nessus version 10.12.0 and lower. An attacker can potentially perform SQL injection via reverse DNS records and scan result files injected by a privileged Nessus user. These attack vectors could allow for the possible exfiltration of scan result data.


