CVE-2011-0549
Published Jul 11, 2011
Last updated 7 years ago
Overview
- Description
- SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF4488B0-2DDE-46A9-BC01-9676D96B1714" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.0.326:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "785F35C9-A23C-4467-9944-135D268415A8" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.1.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72B9BB62-EA23-4608-AA0F-62DDE8D06173" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.1.44:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "218F909A-1A0D-4241-A2AE-BA59A5138361" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.2.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15F751D5-4264-4D10-9E44-807D608EED46" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.2.65:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCA10FE3-5F64-4B84-8C84-DB3F4B5DB4B7" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.2.72:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CC4403C-AABE-40A9-97B7-E4045AEC0943" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.3.38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCCF8646-F0F4-4C55-95C2-13BB0741E221" }, { "criteria": "cpe:2.3:a:symantec:web_gateway:4.5.4.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "274CE264-EF1D-401C-A8FF-C5702B64BAE6" } ], "operator": "OR" } ] } ]