CVE-2010-0147
published 2010-02-23CVE-2010-0147: SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows…
PriorityP335medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.61%
73.2th percentile
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco9.0CRITICAL
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Security Agent
vendor_cisco·2010-02-17·CVSS 9.0
CVE-2010-0146 [CRITICAL] CWE-22 Multiple Vulnerabilities in Cisco Security Agent
Multiple Vulnerabilities in Cisco Security Agent
The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated attacker to execute SQL statements that can cause instability of the product or changes in the configuration.
Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated exploitation co
Red Hat
kernel: sys_move_pages infoleak
vendor_redhat·2010-02-05·CVSS 4.6
CVE-2010-0415 [MEDIUM] kernel: sys_move_pages infoleak
kernel: sys_move_pages infoleak
The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3 and 4, as they do not include support for sys_move_pages. It was only introduced in kernel version 2.6.18 onwards. This issue was addressed in Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2010-0147.html and https://rhn.redhat.com/errata/RHSA-2010-0161.html.
Cisco
Multiple Vulnerabilities in Cisco Security Agent
vendor_cisco
CVE-2010-0147 Multiple Vulnerabilities in Cisco Security Agent
CVE-2010-0147: Multiple Vulnerabilities in Cisco Security Agent
The Management Center for Cisco Security Agents is affected by a directory traversal vulnerability and a SQL injection vulnerability. Successful exploitation of the directory traversal vulnerability may allow an authenticated attacker to view and download arbitrary files from the server hosting the Management Center. Successful exploitation of the SQL injection vulnerability may allow an authenticated attacker to execute SQL statements that can cause instability of the product or changes in the configuration. Additionally, the Cisco Security Agent is affected by a denial of service (DoS) vulnerability. Successful exploitation of the Cisco Security Agent agent DoS vulnerability may cause the affected system to crash. Repeated e
GHSA
GHSA-fg9r-mq2g-292x: SQL injection vulnerability in the Management Center for Cisco Security Agents 5
ghsa_unreviewed·2022-05-02
CVE-2010-0147 [MEDIUM] CWE-89 GHSA-fg9r-mq2g-292x: SQL injection vulnerability in the Management Center for Cisco Security Agents 5
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://osvdb.org/62444http://secunia.com/advisories/38619http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtmlhttp://www.securityfocus.com/bid/38272http://www.securitytracker.com/id?1023606http://www.vupen.com/english/advisories/2010/0416https://exchange.xforce.ibmcloud.com/vulnerabilities/56346http://osvdb.org/62444http://secunia.com/advisories/38619http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtmlhttp://www.securityfocus.com/bid/38272http://www.securitytracker.com/id?1023606http://www.vupen.com/english/advisories/2010/0416https://exchange.xforce.ibmcloud.com/vulnerabilities/56346
2010-02-23
Published