CVE-2015-5452

Watchguard XCS <10.0 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotebsd
https://www.exploit-db.com/exploits/38346
exploitdb WORKING POC
by Security-Assessment.com · textwebappsphp
https://www.exploit-db.com/exploits/37440

Scores

EPSS 0.3667
EPSS Percentile 97.2%

Details

CWE
CWE-89
Status published
Products (2)
watchguard/xcs 9.2
watchguard/xcs 10.0
Published Jul 08, 2015
Tracked Since Feb 18, 2026