RULE(RULE ID:320617)

Rule General Information
Release Date: 2012-12-26
Rule Name: Symantec Web Gateway Blocked.php Blind SQL Injection Vulnerability -3 (CVE-2012-2574)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:54424
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&