Symantec Web Gateway CVE-2013-5012 Multiple SQL Injection Vulnerabilities
BID:65404
Info
Symantec Web Gateway CVE-2013-5012 Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 65404 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5012 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2014 12:00AM |
| Updated: | Feb 10 2014 12:00AM |
| Credit: | Shaun Bertrand of Creative Breakthroughs Inc |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway CVE-2013-5012 Multiple SQL Injection Vulnerabilities
Symantec Web Gateway is prone to multiple unspecified SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway 5.1.1 is vulnerable; prior versions may also be affected.
Symantec Web Gateway is prone to multiple unspecified SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec Web Gateway 5.1.1 is vulnerable; prior versions may also be affected.
Exploit / POC
Symantec Web Gateway CVE-2013-5012 Multiple SQL Injection Vulnerabilities
An attacker can exploit these issues using a Web browser.
An attacker can exploit these issues using a Web browser.
References
Symantec Web Gateway CVE-2013-5012 Multiple SQL Injection Vulnerabilities
References:
References:
- Symantec Web Gateway (Symantec)