Medium
NETGEAR ProSafe FVS336Gv2 and NETGEAR ProSafe FVS336Gv3 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to USERDBDomains.Domain name in cgi-bin/platform.cgi, which could allow the attacker to view, add, modify or delete information in the back-end database.
Upgrade to the latest version of NETGEAR, available from the NETGEAR WebSite.