CVE-2020-35743: HGiga MailSherlock - SQL Injection -3
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-35743?
CVE-2020-35743 is a SQL injection flaw found in HGiga MailSherlock.
How does CVE-2020-35743 impact the affected software?
CVE-2020-35743 allows attackers to inject and launch SQL commands in a URL parameter of specific CGI pages in the affected software.
What is the severity of CVE-2020-35743?
CVE-2020-35743 has a severity rating of 7.6 (high).
Which software versions are affected by CVE-2020-35743?
CVE-2020-35743 affects HGiga Msr45 Isherlock-antispam version up to 4.5-133, HGiga Msr45 Isherlock-user version up to 4.5-120, HGiga Ssr45 Isherlock-antispam version up to 4.5-133, and HGiga Ssr45 Isherlock-user version up to 4.5-120.
How can CVE-2020-35743 be mitigated?
To mitigate CVE-2020-35743, it is recommended to update the affected software to a version that includes a fix for the vulnerability.