Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fixitc

#22443of 53,611
10Total CVSS
Vulnerabilities · 1
PT-2023-8179
10
2023-12-28
Netentsec · Netentsec Ns-Asg Application Security Gateway · CVE-2023-7161
**Name of the Vulnerable Software and Affected Versions** Netentsec NS-ASG Application Security Gateway version 6.3.1 **Description** A critical vulnerability has been found in the Netentsec NS-ASG Application Security Gateway. This issue affects the component Login, specifically the file index.php?para=index, and is related to the lack of protection against SQL injection attacks. The manipulation of the `check VirtualSiteId` argument leads to SQL injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For Netentsec NS-ASG Application Security Gateway version 6.3.1, as a temporary workaround, consider restricting access to the `index.php?para=index` file or disabling the `check VirtualSiteId` argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.