CVE-2015-6548: SQL Injection
Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6548?
CVE-2015-6548 is classified as a high severity vulnerability due to its potential for remote authenticated SQL command execution.
How do I fix CVE-2015-6548?
To fix CVE-2015-6548, upgrade your Symantec Web Gateway to version 5.2.2 or later.
Who is affected by CVE-2015-6548?
CVE-2015-6548 affects users of Symantec Web Gateway appliances running software versions prior to 5.2.2.
What types of attacks can exploit CVE-2015-6548?
CVE-2015-6548 can be exploited through SQL injection attacks, allowing remote authenticated users to execute arbitrary SQL commands.
Is authentication required to exploit CVE-2015-6548?
Yes, exploitation of CVE-2015-6548 requires remote authenticated access to the affected management console.