First published: Tue Feb 23 2010(Updated: )
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Security Agent | =5.1 | |
Cisco Security Agent | =5.2 | |
Cisco Security Agent | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0147 is classified as a high-severity SQL injection vulnerability.
To remediate CVE-2010-0147, upgrade Cisco Security Agent to version 5.1.0.117 or later, 5.2.0.296 or later, or 6.0.1.132 or later.
CVE-2010-0147 affects remote authenticated users of Cisco Security Agent versions 5.1, 5.2, and 6.0 before their respective fixed versions.
CVE-2010-0147 allows attackers to execute arbitrary SQL commands against the underlying database.
While CVE-2010-0147 is not classified as critical, its high-severity rating indicates a significant risk to affected systems.