Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
BID:54721
Info
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
| Bugtraq ID: | 54721 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4178 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2012 12:00AM |
| Updated: | Aug 09 2012 04:22PM |
| Credit: | @_Kc57 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
Symantec Web Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway version 5.0.3.18 is vulnerable; other versions may also be affected.
Symantec Web Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway version 5.0.3.18 is vulnerable; other versions may also be affected.
Exploit / POC
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit is available:
Attackers can use a browser to exploit this issue.
The following exploit is available:
Solution / Fix
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Web Gateway 'deptUploads_data.php' SQL Injection Vulnerability
References:
References:
- Symantec Web Gateway (Symantec)