Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
BID:47780
Info
Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
| Bugtraq ID: | 47780 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2011 12:00AM |
| Updated: | May 16 2011 12:02PM |
| Credit: | @drk1wi |
| Vulnerable: |
Imperva SecureSphere Web Application Firewall 7.0 .7078 on XOS 8.5.3 Imperva SecureSphere Web Application Firewall 6.2 .6442 Imperva SecureSphere Web Application Firewall 6.0.6 .6302 Imperva SecureSphere Web Application Firewall 6.0.6 .6274 Imperva SecureSphere Web Application Firewall 6.0.5 .6238 Imperva SecureSphere Web Application Firewall 6.0.5 .6230 Imperva SecureSphere Web Application Firewall 6.0.4 .6128 on XOS 8.0/5 Imperva SecureSphere Web Application Firewall 6.0.4 .6128 Imperva SecureSphere Web Application Firewall 5.0 .5082 Imperva SecureSphere Web Application Firewall 8.0 Imperva SecureSphere Web Application Firewall 7.5 Imperva SecureSphere Web Application Firewall 7.0.0.7078 Imperva SecureSphere Web Application Firewall 7.0.0.7061 Imperva SecureSphere Web Application Firewall 7.0 Imperva SecureSphere Web Application Firewall 6.2.0.6463 |
| Not Vulnerable: | |
Discussion
Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
Imperva SecureSphere is prone to a security-bypass vulnerability.
An attacker can leverage this vulnerability to bypass certain security restrictions. Successful exploits may allow attackers to exploit SQL-injection vulnerabilities.
Imperva SecureSphere is prone to a security-bypass vulnerability.
An attacker can leverage this vulnerability to bypass certain security restrictions. Successful exploits may allow attackers to exploit SQL-injection vulnerabilities.
Exploit / POC
Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
An attacker can exploit this issue through a browser.
The following example data is available:
15 and '1'=(SELECT '1' FROM dual) and '0having'='0having'
An attacker can exploit this issue through a browser.
The following example data is available:
15 and '1'=(SELECT '1' FROM dual) and '0having'='0having'
Solution / Fix
Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
Solution:
Reports indicate that this issue has been fixed. Please contact the vendor for more information.
Solution:
Reports indicate that this issue has been fixed. Please contact the vendor for more information.
References
Imperva SecureSphere SQL Query Filter Security Bypass Vulnerability
References:
References:
- Vendor Homepage (Imperva)
- Vulnerability Reference (Piotr Duszynski )