Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kc57

#35785de 53,630
7.5CVSS total
Vulnerabilidades · 1
PT-2012-5222
7.5
2012-08-07
Symantec · Symantec Web Gateway · CVE-2012-4178
**Name of the Vulnerable Software and Affected Versions** Symantec Web Gateway version 5.0.3.18 **Description** A SQL injection issue allows remote attackers to execute arbitrary SQL commands. The issue is related to the `groupid` parameter in the `spywall/includes/deptUploads data.php` file. **Recommendations** For Symantec Web Gateway version 5.0.3.18, avoid using the `groupid` parameter in the affected file until the issue is resolved. As a temporary workaround, consider restricting access to the `deptUploads data.php` file to minimize the risk of exploitation.