Summary
This host is installed with Symantec Web
Gateway and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote
attackers to inject or manipulate SQL queries in the back-end database allowing for the manipulation or disclosure of arbitrary data and execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.
Impact Level: Application
Solution
Upgrade to Symantec Web Gateway version
5.2 or later. For updates refer http://www.symantec.com/web-gateway/
Insight
Multiple errors are due to,
- An error in the 'clientreport.php' script which do not properly sanitize user-supplied input before using it in SQL queries.
- An error in program which do not validate input to multiple unspecified report parameters before returning it to users.
Affected
Symantec Web Gateway prior to version
5.2
Detection
Get the installed version with the help
of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-1651, CVE-2014-1652 -
CVSS Base Score: 5.8
AV:A/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities