{"api_version":"1","generated_at":"2026-07-23T10:46:44+00:00","cve":"CVE-2006-0522","urls":{"html":"https://cve.report/CVE-2006-0522","api":"https://cve.report/api/cve/CVE-2006-0522.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0522","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0522"},"summary":{"title":"CVE-2006-0522","description":"SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-02-02 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/22883","name":"http://www.osvdb.org/22883","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24413","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24413","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015561","name":"http://securitytracker.com/id?1015561","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Symantec Sygate Management Server Input Validation Error Lets Remote Users Inject SQL Commands to Gain Administrative Access","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html","name":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Symantec Sygate Management Server:  SMS Authentication Servlet SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16452","name":"http://www.securityfocus.com/bid/16452","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0402","name":"http://www.vupen.com/english/advisories/2006/0402","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18689","name":"http://secunia.com/advisories/18689","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Sygate Management Server SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0522","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0522","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"sygate_management_server","cpe6":"3.5_mr_3_build_894_english","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"sygate_management_server","cpe6":"4.0_mr_1_build_1104_english","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"sygate_management_server","cpe6":"4.1_ga_build_1258_japanese","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"522","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"sygate_management_server","cpe6":"4.1_mr1_build_1351_chinese","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"522","vulnerable":"1","versionEndIncluding":"4.1_mr_2_build_1417_english","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"sygate_management_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"522","cve":"CVE-2006-0522","epss":"0.016900000","percentile":"0.822630000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:41:27.672Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1015561","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015561"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html"},{"name":"16452","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16452"},{"name":"18689","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18689"},{"name":"symantec-sms-sql-injection(24413)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24413"},{"name":"22883","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/22883"},{"name":"ADV-2006-0402","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0402"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1015561","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015561"},{"tags":["x_refsource_CONFIRM"],"url":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html"},{"name":"16452","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16452"},{"name":"18689","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18689"},{"name":"symantec-sms-sql-injection(24413)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24413"},{"name":"22883","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/22883"},{"name":"ADV-2006-0402","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0402"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0522","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1015561","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015561"},{"name":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html","refsource":"CONFIRM","url":"http://securityresponse.symantec.com/avcenter/security/Content/2006.02.01.html"},{"name":"16452","refsource":"BID","url":"http://www.securityfocus.com/bid/16452"},{"name":"18689","refsource":"SECUNIA","url":"http://secunia.com/advisories/18689"},{"name":"symantec-sms-sql-injection(24413)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24413"},{"name":"22883","refsource":"OSVDB","url":"http://www.osvdb.org/22883"},{"name":"ADV-2006-0402","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0402"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0522","datePublished":"2006-02-02T11:00:00.000Z","dateReserved":"2006-02-02T00:00:00.000Z","dateUpdated":"2024-08-07T16:41:27.672Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-02-02 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:sygate_management_server:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1_mr_2_build_1417_english","matchCriteriaId":"4FD9E5B5-20DD-4D3C-9D10-08A043B51C88"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:sygate_management_server:3.5_mr_3_build_894_english:*:*:*:*:*:*:*","matchCriteriaId":"4EAFFADA-1F18-444D-917D-5AEA1CC1A0B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:sygate_management_server:4.0_mr_1_build_1104_english:*:*:*:*:*:*:*","matchCriteriaId":"5B1958B8-31A2-4C36-81A8-EDA3001DED74"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:sygate_management_server:4.1_ga_build_1258_japanese:*:*:*:*:*:*:*","matchCriteriaId":"80AC3305-3F74-4502-BB0B-E2E2C3FB9941"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:sygate_management_server:4.1_mr1_build_1351_chinese:*:*:*:*:*:*:*","matchCriteriaId":"A8DA3C4A-3493-48AD-8B9C-CE8F494F036D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"522","Ordinal":"1","Title":"CVE-2006-0522","CVE":"CVE-2006-0522","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"522","Ordinal":"1","NoteData":"SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.","Type":"Description","Title":"CVE-2006-0522"},{"CveYear":"2006","CveId":"522","Ordinal":"2","NoteData":"2006-02-02","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"522","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}