First published: Wed Aug 15 2012(Updated: )
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | =15.02 | |
Progress Software WhatsUp Gold | =15.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2601 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To mitigate CVE-2012-2601, upgrade to a patched version of Ipswitch WhatsUp Gold that addresses this SQL injection vulnerability.
CVE-2012-2601 affects Ipswitch WhatsUp Gold version 15.02.
CVE-2012-2601 is classified as an SQL injection vulnerability.
Yes, CVE-2012-2601 can be exploited remotely by attackers targeting the sGroupList parameter.