SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
| Software | From | Fixed in |
|---|---|---|
| cisco / security_manager | 4.6 | 4.6.x |
| cisco / security_manager | 4.5 | 4.5.x |