CVE-2012-4178
Symantec Web Gateway 5.0.3.18 - SQL Injection via groupid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4178. PoCs published by Kc57.
AI-analyzed exploit summary This is a Python script that exploits a blind SQL injection vulnerability in the 'spywall' application. It uses time-based techniques to extract the first user's password hash from the database by checking each character position.
Description
SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
Exploits (1)
This is a Python script that exploits a blind SQL injection vulnerability in the 'spywall' application. It uses time-based techniques to extract the first user's password hash from the database by checking each character position.