CVE-2012-2961: SQL Injection
Published Jul 23, 2012
·Updated
SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
4 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Symantec Web Gateway=5.0.3
Event History
Jul 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2961?
CVE-2012-2961 is classified as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2012-2961?
To remediate CVE-2012-2961, upgrade Symantec Web Gateway to version 5.0.3.18 or later.
3
What software is affected by CVE-2012-2961?
CVE-2012-2961 affects Symantec Web Gateway versions 5.0.x through 5.0.3.17.
4
What type of vulnerability is CVE-2012-2961?
CVE-2012-2961 is an SQL injection vulnerability that allows attackers to manipulate database queries.
5
Can CVE-2012-2961 lead to data breaches?
Yes, successful exploitation of CVE-2012-2961 can lead to data breaches due to unauthorized access to sensitive database information.