CVE-2015-6811

Cyberoamos - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.

Exploits (1)

exploitdb WRITEUP
by Dharmendra Kumar Singh · textwebappshardware
https://www.exploit-db.com/exploits/38034

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38034/

Scores

EPSS 0.0178
EPSS Percentile 82.8%

Details

CWE
CWE-89
Status published
Products (1)
cyberoam/cyberoamos 10.6.2 (5 CPE variants)
Published Sep 04, 2015
Tracked Since Feb 18, 2026