Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Symantec Web Gateway forget.php Blind SQL Injection (SYM11-008)



The web security application running on the remote host has a SQL injection vulnerability.


Versions of Symantec Web Gateway 4.5.x are potentially affected by a SQL injection vulnerability. Input to the 'username' parameter of the 'forget.php' script is not properly sanitized. A remote, unauthenticated attacker could exploit this to execute arbitrary SQL queries.


Upgrade to Symantec Web Gateway version 5.0.1 or later.