CVE-2016-1000000: SQL Injection
Published Oct 6, 2016
·Updated
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
Affected Software
2 affected components
Progress WhatsUp Gold<=16.4
Ipswitch WhatsUp Gold<=16.4
Event History
Oct 6, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1000000?
CVE-2016-1000000 is classified as a high-severity vulnerability due to its potential for exploitation through SQL injection.
2
How do I fix CVE-2016-1000000?
To fix CVE-2016-1000000, it's recommended to update WhatsUp Gold to version 16.4.2 or later.
3
What is affected by CVE-2016-1000000?
CVE-2016-1000000 affects Ipswitch WhatsUp Gold versions up to and including 16.4.
4
What type of vulnerability is CVE-2016-1000000?
CVE-2016-1000000 is a blind SQL injection vulnerability affecting the sUniqueID parameter in WrFreeFormText.asp.
5
Can CVE-2016-1000000 be exploited remotely?
Yes, CVE-2016-1000000 can be exploited remotely without authentication, allowing attackers to potentially manipulate the database.