PT-2016-4489 · Ipswitch · Ipswitch Whatsup Gold
CVE-2016-1000000
·
Publicado
2016-10-06
·
Atualizado
2024-08-27
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ipswitch WhatsUp Gold version 16.4.1
Description
The issue is related to a Blind SQL Injection in the
sUniqueID parameter of the WrFreeFormText.asp page. This allows for potential unauthorized access to database information.Recommendations
For Ipswitch WhatsUp Gold version 16.4.1, consider restricting access to the WrFreeFormText.asp page until a patch is available. As a temporary workaround, avoid using the
sUniqueID parameter in the affected API endpoint until the issue is resolved.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ipswitch Whatsup Gold