Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Symantec Endpoint Protection Manager组件SQL注入漏洞
Vulnerability Description
Symantec Endpoint Protection(SEP)是美国赛门铁克(Symantec)公司的一套防病毒软件。该软件可跨物理和虚拟系统提供安全防护功能。Manager是其中的一个管理服务器控制台组件。 SEP 12.1.6之前版本的Manager组件中的界面PHP脚本中存在SQL注入漏洞。远程攻击者可借助Limited Administrator角色利用该漏洞执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A