First published: Thu Dec 31 2020(Updated: )
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Hgiga Msr45 Isherlock-antispam | <4.5-133 | |
Hgiga Msr45 Isherlock-user | <4.5-120 | |
Hgiga Ssr45 Isherlock-antispam | <4.5-133 | |
Hgiga Ssr45 Isherlock-user | <4.5-120 |
Update MailSherlock MSR45/SSR45 Module to: iSherlock-user-4.5-120.i386.rpm iSherlock-antispam-4.5-133.i386.rpm
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35743 is a SQL injection flaw found in HGiga MailSherlock.
CVE-2020-35743 allows attackers to inject and launch SQL commands in a URL parameter of specific CGI pages in the affected software.
CVE-2020-35743 has a severity rating of 7.6 (high).
CVE-2020-35743 affects HGiga Msr45 Isherlock-antispam version up to 4.5-133, HGiga Msr45 Isherlock-user version up to 4.5-120, HGiga Ssr45 Isherlock-antispam version up to 4.5-133, and HGiga Ssr45 Isherlock-user version up to 4.5-120.
To mitigate CVE-2020-35743, it is recommended to update the affected software to a version that includes a fix for the vulnerability.