PT-2006-6432 · Highwall · Highwall Enterprise+1
Published
2006-11-06
·
Updated
2018-10-17
·
CVE-2006-5744
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Highwall Enterprise version 4.0.2.11045
Highwall Endpoint version 4.0.2.11045
Description:
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via an Access Point with a crafted SSID or through unspecified vectors related to a malicious system operator.
Recommendations:
For Highwall Enterprise version 4.0.2.11045, consider restricting access to the management interface to minimize the risk of exploitation.
For Highwall Endpoint version 4.0.2.11045, avoid using crafted SSIDs for Access Points until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Highwall Endpoint
Highwall Enterprise