RULE(RULE ID:322089)

Rule General Information
Release Date: 2019-06-27
Rule Name: Symantec Web Gateway ldap_latest.php Blind SQLi Injection Vulnerability (CVE-2012-2961)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:54425
http://www.kb.cert.org/vuls/id/108471
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120720_00
https://exchange.xforce.ibmcloud.com/vulnerabilities/77116
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid;=security_advisory&suid;=20120720_00