CVE-2011-0549: SQL Injection
SQL injection vulnerability in forget.php in the management GUI in Symantec Web Gateway 4.5.x allows remote attackers to execute arbitrary SQL commands via the username parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0549?
CVE-2011-0549 is classified as a critical severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2011-0549?
To fix CVE-2011-0549, users should apply the latest security patch provided by Symantec for Web Gateway versions affected.
Which versions of Symantec Web Gateway are affected by CVE-2011-0549?
CVE-2011-0549 affects Symantec Web Gateway versions 4.5, 4.5.0.326, 4.5.1.34, 4.5.1.44, 4.5.2.37, 4.5.2.65, 4.5.2.72, 4.5.3.38, and 4.5.4.9.
How can attackers exploit CVE-2011-0549?
Attackers can exploit CVE-2011-0549 by sending specially crafted SQL queries through the username parameter in forget.php.
What are the potential impacts of CVE-2011-0549?
The potential impacts of CVE-2011-0549 include unauthorized data access, data manipulation, and compromising the integrity of the database.