CVE-2015-2849

ANTlabs InnGate - SQL Injection via ppli Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in main.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices, when https is used, allows remote attackers to execute arbitrary SQL commands via the ppli parameter.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/485324

Scores

EPSS 0.0135
EPSS Percentile 68.6%

Details

CWE
CWE-89
Status published
Products (6)
antlabs/inngate_ig_3.01_e
antlabs/inngate_ig_3.10_e
antlabs/inngate_ig_3.10_m
antlabs/inngate_ig_3100
antlabs/inngate_sg_4
antlabs/inngate_ssg_4
Published Jul 07, 2015
Tracked Since Feb 18, 2026