Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.804406
Kategorie:Web application abuses
Titel:Symantec Web Gateway Cross-Site Scripting and SQL Injection Vulnerabilities
Zusammenfassung:This host is running Symantec Web Gateway and is prone to cross-site scripting; and SQL injection vulnerabilities.
Beschreibung:Summary:
This host is running Symantec Web Gateway and is prone to cross-site scripting
and SQL injection vulnerabilities.

Vulnerability Insight:
Flaws are due to:

- Certain unspecified input is not properly sanitised before being returned
to the user.

- An input passed via the 'operand[]' parameter to /spywall/blacklist.php is
not properly sanitised before being returned to the user.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary code in
the context of the application, bypass certain security restrictions and
conduct SQL injection attacks.

Affected Software/OS:
Symantec Web Gateway versions prior to 5.2

Solution:
Upgrade to Symantec Web Gateway 5.2 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Querverweis: BugTraq ID: 65404
BugTraq ID: 65405
Common Vulnerability Exposure (CVE) ID: CVE-2013-5012
http://www.securityfocus.com/bid/65404
Common Vulnerability Exposure (CVE) ID: CVE-2013-5013
http://www.securityfocus.com/bid/65405
http://osvdb.org/103144
http://osvdb.org/103145
http://osvdb.org/103147
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.