VulnerabilityModified
CVE-2006-0581
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.
MEDIUM 6.5EPSS 1.82%
Does this matter?
Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- hosting controller/hosting controller
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18731Vendor Advisory
- http://securitytracker.com/id?1015584Exploit
- http://www.osvdb.org/22982
- http://www.osvdb.org/22983
- http://www.vupen.com/english/advisories/2006/0460
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24537
- http://secunia.com/advisories/18731Vendor Advisory
- http://securitytracker.com/id?1015584Exploit
- http://www.osvdb.org/22982
- http://www.osvdb.org/22983
- http://www.vupen.com/english/advisories/2006/0460
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24537
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.