Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
BID:54425
Info
Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
| Bugtraq ID: | 54425 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2961 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2012 12:00AM |
| Updated: | Jul 24 2012 06:50PM |
| Credit: | Offensive Security |
| Vulnerable: |
Symantec Web Gateway 5.0.3 Symantec Web Gateway 5.0.1 |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
Symantec Web Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Symantec Web Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Exploit / POC
Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example data is available:
Attackers can use a browser to exploit this issue.
The following example data is available:
Solution / Fix
Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Web Gateway CVE-2012-2961 SQL Injection Vulnerability
References:
References:
- Symantec Web Gateway (Symantec)