CVE-2015-6028
HIGHCastle Rock Computing SNMPc <2015-12-17 - SQL Injection
Title source: llmDescription
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
References (1)
Core 1
Core References
Technical Description, Third Party Advisory x_refsource_misc
https://community.rapid7.com/community/infosec/blog/2015/12/16/multiple-disclosures-for-multiple-network-management-systems
Scores
CVSS v3
8.8
EPSS
0.0111
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (3)
castlerock/snmpc
9.0
castlerock/snmpc
12.1
n/a/Castle Rock Computing SNMPc before 2015-12-17
Castle Rock Computing SNMPc before 2015-12-17
Published
Apr 10, 2017
Tracked Since
Feb 18, 2026