Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.
Metrics
Affected Vendors & Products
References
History
Tue, 27 Aug 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Progress
Progress whatsup Gold |
|
CPEs | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ipswitch
Ipswitch whatsup Gold |
Progress
Progress whatsup Gold |
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2015-12-27T02:00:00
Updated: 2024-08-06T07:06:35.184Z
Reserved: 2015-08-14T00:00:00
Link: CVE-2015-6004
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-12-27T03:59:00.113
Modified: 2024-11-21T02:34:16.707
Link: CVE-2015-6004
Redhat
No data.