CVE-2006-0522 describes a critical SQL injection vulnerability in the Authentication Servlet of Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary SQL commands and bypass authentication mechanisms. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, an exploit module for Metasploit is available on ExploitDB, indicating public knowledge of exploitation methods. Despite this, there is no evidence of active exploitation, significant community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.1_mr_2_build_1417_englishCPE matchmatch criteria | cpe:2.3:a:symantec:sygate_management_server:*:*:*:*:*:*:*:* | ||
3.5_mr_3_build_894_englishCPE matchmatch criteria | cpe:2.3:a:symantec:sygate_management_server:3.5_mr_3_build_894_english:*:*:*:*:*:*:* | ||
4.0_mr_1_build_1104_englishCPE matchmatch criteria | cpe:2.3:a:symantec:sygate_management_server:4.0_mr_1_build_1104_english:*:*:*:*:*:*:* | ||
4.1_ga_build_1258_japaneseCPE matchmatch criteria | cpe:2.3:a:symantec:sygate_management_server:4.1_ga_build_1258_japanese:*:*:*:*:*:*:* | ||
4.1_mr1_build_1351_chineseCPE matchmatch criteria | cpe:2.3:a:symantec:sygate_management_server:4.1_mr1_build_1351_chinese:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.