SQL Injection Vulnerabilities in Novell ZENworks Patch Management
CVE-2006-6450
Currently unrated
Key Information:
- Vendor
- Novell
- Vendor
- CVE Published:
- 10 December 2006
Summary
Multiple SQL injection vulnerabilities exist in the downloadreport.asp script of Novell ZENworks Patch Management prior to version 6.3.2.700. These vulnerabilities could allow remote attackers to manipulate the SQL queries through the agentid and pass parameters, enabling them to execute arbitrary SQL commands. This poses significant risks to data integrity and system security, as attackers may exploit these weaknesses to gain unauthorized access to sensitive information or perform administrative operations.
References
EPSS Score
9% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved