CVE-2010-0115: SQL Injection
Published Jan 14, 2011
·Updated
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
Affected Software
5 affected components
Symantec Web Gateway=4.5
Symantec Web Gateway=4.5.0.325
Symantec Web Gateway=4.5.0.326
Symantec Web Gateway=4.5.0.327
Symantec Web Gateway Appliance
Event History
Jan 14, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
11:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0115?
CVE-2010-0115 is considered a high severity vulnerability due to its potential for remote code execution through SQL injection.
2
How do I fix CVE-2010-0115?
To fix CVE-2010-0115, update Symantec Web Gateway to version 4.5.0.376 or later.
3
What software versions are affected by CVE-2010-0115?
CVE-2010-0115 affects Symantec Web Gateway versions 4.5, 4.5.0.325, 4.5.0.326, and 4.5.0.327.
4
What type of vulnerability is CVE-2010-0115?
CVE-2010-0115 is an SQL injection vulnerability found in the login.php file of the Symantec Web Gateway management console.
5
Can CVE-2010-0115 be exploited remotely?
Yes, CVE-2010-0115 allows remote attackers to execute arbitrary SQL commands via vulnerabilities in user input handling.