First published: Wed Jul 08 2015(Updated: )
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard XCS | =9.2 | |
WatchGuard XCS | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5452 is considered a critical SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
To fix CVE-2015-5452, upgrade Watchguard XCS to version 9.2 build 150522 or later, or version 10.0 build 150522 or later.
CVE-2015-5452 affects Watchguard XCS versions 9.2 and 10.0 before build 150522.
CVE-2015-5452 allows exploitation through a vulnerable sid cookie sent to the borderpost/imp/compose.php3 page, enabling SQL command execution.
Mitigation of CVE-2015-5452 without an upgrade is not recommended, as it is best addressed through the installation of security patches.