SQL Injection Vulnerability in Cisco Secure Access Control Server
CVE-2015-6345
Currently unrated
What is CVE-2015-6345?
A SQL injection vulnerability exists in the Solution Engine of Cisco Secure Access Control Server, specifically in version 5.7(0.15). This security issue enables remote authenticated users to execute arbitrary SQL commands through specially crafted URLs. The exploitation of this vulnerability can lead to unauthorized data access or alteration within the affected system. Users are advised to apply patches and monitor their systems for suspicious activity to mitigate potential risks.