SQL Injection Vulnerabilities in Novell ZENworks Patch Management
CVE-2006-6450

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
10 December 2006

Summary

Multiple SQL injection vulnerabilities exist in the downloadreport.asp script of Novell ZENworks Patch Management prior to version 6.3.2.700. These vulnerabilities could allow remote attackers to manipulate the SQL queries through the agentid and pass parameters, enabling them to execute arbitrary SQL commands. This poses significant risks to data integrity and system security, as attackers may exploit these weaknesses to gain unauthorized access to sensitive information or perform administrative operations.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.