Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zenworks_patch_management_server | Novell | 6.0.0.52 (including) | 6.0.0.52 (including) |