1 results (0.004 seconds)

CVSS: 9.8EPSS: 0%CPEs: 23EXPL: 0

03 Dec 2014 — SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. Vulnerabilidad de inyección SQL en OpenVAS Manager anterior a 4.0.6 y 5.x anterior a 5.0.7 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro timezone en un comando OMP modify_schedule. • http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147753.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •