Symantec.Web.Gateway.blocked.php.Blind.SQL.Injection
Description
This indicates an attack attempt to exploit a SQL Injection vulnerability in Symantec Web Gateway.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application when handling a malicious HTTP request with a crafted "id" parameter. A remote attacker can exploit this to send a crafted query to execute SQL commands on a vulnerable server.
Affected Products
Symantec Web Gateway 5.0.3.18 prior to database update 5.0.0.438
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&suid=20120720_00
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |