Symantec Web Gateway Cross-Site Scripting and SQL Injection Vulnerabilities

Summary
This host is running Symantec Web Gateway and is prone to cross-site scripting and SQL injection vulnerabilities.
Impact
Successful exploitation will allow attackers to execute arbitrary code in the context of the application, bypass certain security restrictions and conduct SQL injection attacks. Impact Level: Application
Solution
Upgrade to Symantec Web Gateway 5.2 or later, For updates refer to http://www.symantec.com/business/web-gateway
Insight
Flaws are due to, - Certain unspecified input is not properly sanitised before being returned to the user. - An input passed via the 'operand[]' parameter to /spywall/blacklist.php is not properly sanitised before being returned to the user.
Affected
Symantec Web Gateway versions prior to 5.2
Detection
Send a crafted data via HTTP GET request and check whether it is able to read cookie or not.
References