Back

CVE-2006-0522

SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.

Published: Feb 2, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
symantec sygate_management_server *
symantec sygate_management_server 3.5_mr_3_build_894_english
symantec sygate_management_server 4.0_mr_1_build_1104_english
symantec sygate_management_server 4.1_ga_build_1258_japanese
symantec sygate_management_server 4.1_mr1_build_1351_chinese

GitHub Security Advisory GHSA-73wf-vqvh-77wf

SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.75%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub