Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款Symantec产品SQL注入漏洞
Vulnerability Description
Symantec Critical System Protection(SCSP)和Symantec Data Center Security: Server Advanced(SDCS:SA)都是美国赛门铁克(Symantec)公司的安全产品。SCSP是一套入侵检测和防御系统;SDCS:SA为软件定义数据中心的物理和虚拟服务器提供了安全防护。 多款Symantec产品中存在SQL注入漏洞。远程攻击者可通过发送特制的HTTP请求利用该漏洞执行任意SQL命令,在服务器中添加管理员账户。以下产品和版本受到影响
CVSS Information
N/A
Vulnerability Type
N/A