CVE-2006-0522 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.75% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| symantec | sygate management server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Symantec Sygate Management Server - 'LOGIN' SQL Injection (Metasploit) | 2006-04-15 |
References
- http://secunia.com/advisories/18689
- http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html
- http://securitytracker.com/id?1015561
- http://www.osvdb.org/22883
- http://www.securityfocus.com/bid/16452
- http://www.vupen.com/english/advisories/2006/0402
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24413
- http://secunia.com/advisories/18689
- http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html
- http://securitytracker.com/id?1015561
- http://www.osvdb.org/22883
- http://www.securityfocus.com/bid/16452
- http://www.vupen.com/english/advisories/2006/0402
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24413
→ the Explorer · watch your stack · NVD