RULE(RULE ID:322088)

Rule General Information
Release Date: 2019-06-27
Rule Name: Dell SonicWALL Scrutinizer statusFilter.php SQL Injection Vulnerability (CVE-2012-2962)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: ExploitDB:20033
SecurityFocusBID:54625
http://www.kb.cert.org/vuls/id/404051
http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.kb.cert.org/vuls/id/404051