VulnerabilityModified
CVE-2010-0115
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
HIGH 7.5EPSS 2.36%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- symantec/web gateway
- Source
- cve@mitre.org
References
- http://osvdb.org/70415
- http://secunia.com/advisories/42878Vendor Advisory
- http://www.securityfocus.com/bid/45742
- http://www.securitytracker.com/id?1024958
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110112_00
- http://www.vupen.com/english/advisories/2011/0088Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-013/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64658
- http://osvdb.org/70415
- http://secunia.com/advisories/42878Vendor Advisory
- http://www.securityfocus.com/bid/45742
- http://www.securitytracker.com/id?1024958
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110112_00
- http://www.vupen.com/english/advisories/2011/0088Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-11-013/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64658
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.