CVE-2018-5778

CRITICAL

Ipswitch WhatsUp Gold <17.1.1 - SQL Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0012
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
progress/whatsup_gold < 17.1.1
Published Jan 24, 2018
Tracked Since Feb 18, 2026