CVE-2006-6152

HIGH
CVSS v3
7.5CVSS v2
1.10% EPSS (exploit probability)
CWE

Description

Multiple SQL injection vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to (a) cat.asp, or the (2) keyword, (3) order, (4) sort, (5) menuSelect, or (6) state parameter to (b) search.asp.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Ubiquiti Ubiquiti EdgeRouter 4 Likely Patched

External references