CVE-2020-35742: HGiga MailSherlock - SQL Injection -1
Published Dec 31, 2020
·Updated
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
Affected Software
4 affected components
Hgiga Msr45 Isherlock-antispam<4.5-133
Hgiga Msr45 Isherlock-user<4.5-120
Hgiga Ssr45 Isherlock-antispam<4.5-133
Hgiga Ssr45 Isherlock-user<4.5-120
Remediation
Information
Update MailSherlock MSR45/SSR45 Module to:
iSherlock-user-4.5-120.i386.rpm
iSherlock-antispam-4.5-133.i386.rpm
Event History
Dec 31, 2020
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-35742?
CVE-2020-35742 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2020-35742?
To fix CVE-2020-35742, update your Hgiga MailSherlock software to a version greater than 4.5-133 for antispam or greater than 4.5-120 for user.
3
What types of attacks can exploit CVE-2020-35742?
CVE-2020-35742 can be exploited through SQL injection attacks by injecting malicious SQL commands via URL parameters.
4
Which software versions are affected by CVE-2020-35742?
CVE-2020-35742 affects Hgiga Msr45 and Ssr45 Isherlock-antispam versions up to 4.5-133 and user versions up to 4.5-120.
5
Is CVE-2020-35742 easy to exploit?
Yes, CVE-2020-35742 is relatively easy to exploit for attackers with knowledge of SQL injection techniques.