CVE-2010-0115

EUVD-2010-0147
SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
symantecweb_gateway
4.5
symantecweb_gateway
4.5.0.325
symantecweb_gateway
4.5.0.326
symantecweb_gateway
4.5.0.327
𝑥
= Vulnerable software versions