CVE-2012-4178: SQL Injection
Published Aug 7, 2012
·Updated
SQL injection vulnerability in spywall/includes/deptUploadsdata.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.
Affected Software
1 affected component
Symantec Web Gateway=5.0.3.18
Event History
Aug 7, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4178?
CVE-2012-4178 is considered a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2012-4178?
To fix CVE-2012-4178, update Symantec Web Gateway to a version that addresses this SQL injection vulnerability.
3
What versions are affected by CVE-2012-4178?
CVE-2012-4178 specifically affects Symantec Web Gateway version 5.0.3.18.
4
What is the impact of CVE-2012-4178?
The impact of CVE-2012-4178 includes the potential for unauthorized access to the database through arbitrary SQL commands.
5
Who can exploit CVE-2012-4178?
CVE-2012-4178 can be exploited by remote attackers who can send crafted requests to the vulnerable Symantec Web Gateway.