CVE-2015-5452
Watchguard XCS <10.0 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotebsd
https://www.exploit-db.com/exploits/38346
exploitdb
WORKING POC
by Security-Assessment.com · textwebappsphp
https://www.exploit-db.com/exploits/37440
References (8)
Scores
EPSS
0.3667
EPSS Percentile
97.2%
Details
CWE
CWE-89
Status
published
Products (2)
watchguard/xcs
9.2
watchguard/xcs
10.0
Published
Jul 08, 2015
Tracked Since
Feb 18, 2026