CVE-2012-2574: SQL Injection
Published Jul 23, 2012
·Updated
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.
Affected Software
4 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Symantec Web Gateway=5.0.3
Event History
Jul 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2574?
CVE-2012-2574 has a high severity rating due to its potential for remote SQL command execution.
2
How do I fix CVE-2012-2574?
To fix CVE-2012-2574, upgrade Symantec Web Gateway to version 5.0.3.18 or later.
3
What software is affected by CVE-2012-2574?
CVE-2012-2574 affects Symantec Web Gateway versions 5.0, 5.0.1, 5.0.2, and 5.0.3.
4
What kind of attack does CVE-2012-2574 enable?
CVE-2012-2574 enables blind SQL injection attacks allowing execution of arbitrary SQL commands.
5
When was CVE-2012-2574 disclosed?
CVE-2012-2574 was disclosed on July 20, 2012.