Логотип exploitDog
bind:CVE-2020-3154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-3154

Количество 3

Количество 3

nvd логотип

CVE-2020-3154

почти 6 лет назад

A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending malicious requests to the affected device. An exploit could allow the attacker to modify values on or return values from the underlying database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-555v-24ph-xqcc

больше 3 лет назад

A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending malicious requests to the affected device. An exploit could allow the attacker to modify values on or return values from the underlying database.

EPSS: Низкий
fstec логотип

BDU:2020-01155

почти 6 лет назад

Уязвимость веб-интерфейса облачной системы обеспечения интернет-безопасности Cisco Cloud Web Security, позволяющая нарушителю выполнить произвольные SQL-запросы

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-3154

A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending malicious requests to the affected device. An exploit could allow the attacker to modify values on or return values from the underlying database.

CVSS3: 4.9
0%
Низкий
почти 6 лет назад
github логотип
GHSA-555v-24ph-xqcc

A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could exploit this vulnerability sending malicious requests to the affected device. An exploit could allow the attacker to modify values on or return values from the underlying database.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-01155

Уязвимость веб-интерфейса облачной системы обеспечения интернет-безопасности Cisco Cloud Web Security, позволяющая нарушителю выполнить произвольные SQL-запросы

CVSS3: 4.9
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу