Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ipswitch WhatsUp Gold 跨站脚本漏洞
Vulnerability Description
Ipswitch WhatsUp Gold是美国Ipswitch公司的一套统一的基础设施和应用监控软件。该软件支持对网络、服务器、虚拟环境和应用程序的性能进行管理等。 IPSwitch WhatsUp Gold 16.4之前版本中存在SQL注入漏洞,该漏洞源于Reports组件中的WrFreeFormText.asp文件没有充分过滤‘UniqueID’参数;程序没有充分过滤‘Find Device’参数。远程攻击者可利用该漏洞执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A