Описание
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.
Ссылки
- ExploitPatchVendor Advisory
- PatchVendor Advisory
- Patch
- US Government Resource
- ExploitPatchVendor Advisory
- PatchVendor Advisory
- Patch
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:novell:zenworks_patch_management_server:6.0.0.52:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.08984
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.
EPSS
Процентиль: 92%
0.08984
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other