Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.
History

Tue, 27 Aug 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress whatsup Gold
CPEs cpe:2.3:a:ipswitch:whatsup_gold:*:*:*:*:*:*:*:* cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*
Vendors & Products Ipswitch
Ipswitch whatsup Gold
Progress
Progress whatsup Gold

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2015-12-27T02:00:00

Updated: 2024-08-06T07:06:35.184Z

Reserved: 2015-08-14T00:00:00

Link: CVE-2015-6004

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-12-27T03:59:00.113

Modified: 2024-08-27T17:48:24.383

Link: CVE-2015-6004

cve-icon Redhat

No data.