20123exploit
http://www.exploit-db.com/exploits/20123 CVE-2012-4178
Symantec Web Gateway 5.0.3.18 - 'deptUploads_data.php?groupid' Blind SQL Injection
Record summary
CVE-2012-4178 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSymantec Web Gateway 5.0.3.18 - 'deptUploads_data.php?groupid' Blind SQL InjectionExploitDB exploitby Kc57Not analyzed1 file
References
554721vdb entry
http://www.securityfocus.com/bid/54721 1027358vdb entry
http://www.securitytracker.com/id?1027358 symantec-deptuploads-sql-injection(77264)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/77264 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-4178